무슨 일이 있었나
NVD는 2026년 8월 6일 CVE-2026-18976 및 CVE-2026-18993 (모두 CVSS 6.3, Medium)을 발표했습니다. 이는 NousResearch의 hermes-agent toolset 핸들링의 권한 할당 및 액세스 제어 결함을 설명합니다. 특히, 이는 Unit 42가 별도로 보고한 Chinese threat actor에 의해 대량 익스플로잇을 위해 DeepSeek을 연결하도록 weaponized된 same agent 프레임워크입니다 (이전에 보고됨).
왜 중요한가
hermes-agent의 문서화된 autonomous attack 플랫폼으로서의 사용과 live mass-exploitation
공격 경로
get_tool_definitions in the disabled_toolsets handler incorrectly assigns privileges, and a related flaw (CVE-2026-18993) in the Memory Toolset lacks proper access controls, both remotely exploitable.
영향받는 시스템
NousResearch hermes-agent ≤ 0.16.0
완화 방안
Upgrade to a patched hermes-agent release.