Vulnerability  ·  2026-10-11

9router Hermes Agent config injection → arbitrary shell command execution after each LLM call (CVSS 6.4)

VulnerabilityHigh impactGlobalCVE-2026-108593
Verified via NVD REST API (published 2026-10-10, VulnCheck). A config-injection flaw turns LLM-router dashboard access into post-LLM-call command execution inside the Hermes Agent process.
LLM routers sit between applications and model endpoints; code exec in the agent-managed host after each LLM call is a persistent backdoor on the AI request path, and the attack needs only a dashboard account.
The hermes-settings endpoint serializes attacker-controlled baseUrl into the Hermes Agent config.yaml: a baseUrl containing double quotes and newlines injects hooks_auto_accept plus a hooks.post_llm_call shell command that Hermes Agent executes without approval after an LLM call (CWE-94).
9router 0.4.1 through 0.5.99 (POST /api/cli-tools/hermes-settings)
Upgrade past 0.5.99; validate YAML string fields and forbid newline/quote injection before writing agent config. See VulnCheck advisory.
NVD CVE-2026-108593NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →