What happened
Published Sept 3, 2026 (CVSS 7.3), disclosed via VulDB, part of a broader cluster of Hermes Agent vulnerabilities disclosed in this window alongside the separate GitSpawn RCE (CVE-2026-71963).
Why it matters
Combined with the concurrently-disclosed GitSpawn RCE and SSRF findings, this reflects a broader pattern of security debt in Hermes Agent, an actively-used AI agent framework whose vendor has been slow/unresponsive to multiple concurrent security disclosures.
Attack vector
The _sess_nowait function in s71.py mishandles the session_id argument, allowing remote authorization bypass of session management controls.
Affected systems
NousResearch hermes-agent 0.18.0
Mitigation
Update to a patched Hermes Agent release when available; vendor has been unresponsive to security contact attempts per related GitSpawn disclosure.