Vulnerability  ·  2026-09-04

Hermes Agent additional flaws: session authorization bypass and SSRF via link-title fetch

VulnerabilityMedium impactGlobalCVE-2026-85105
Published Sept 3, 2026 (CVSS 7.3), disclosed via VulDB, part of a broader cluster of Hermes Agent vulnerabilities disclosed in this window alongside the separate GitSpawn RCE (CVE-2026-71963).
Combined with the concurrently-disclosed GitSpawn RCE and SSRF findings, this reflects a broader pattern of security debt in Hermes Agent, an actively-used AI agent framework whose vendor has been slow/unresponsive to multiple concurrent security disclosures.
The _sess_nowait function in s71.py mishandles the session_id argument, allowing remote authorization bypass of session management controls.
NousResearch hermes-agent 0.18.0
Update to a patched Hermes Agent release when available; vendor has been unresponsive to security contact attempts per related GitSpawn disclosure.
NVDVulDB
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →