What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck). A config-injection flaw turns LLM-router dashboard access into post-LLM-call command execution inside the Hermes Agent process.
Why it matters
LLM routers sit between applications and model endpoints; code exec in the agent-managed host after each LLM call is a persistent backdoor on the AI request path, and the attack needs only a dashboard account.
Attack vector
The hermes-settings endpoint serializes attacker-controlled baseUrl into the Hermes Agent config.yaml: a baseUrl containing double quotes and newlines injects hooks_auto_accept plus a hooks.post_llm_call shell command that Hermes Agent executes without approval after an LLM call (CWE-94).
Affected systems
9router 0.4.1 through 0.5.99 (POST /api/cli-tools/hermes-settings)
Mitigation
Upgrade past 0.5.99; validate YAML string fields and forbid newline/quote injection before writing agent config. See VulnCheck advisory.