취약점  ·  2026-08-08

NousResearch hermes-agent — 잘못된 권한 할당 및 부적절한 Memory Toolset 액세스 제어

취약점Medium 영향도GlobalCVE-2026-18976
NVD는 2026년 8월 6일 CVE-2026-18976 및 CVE-2026-18993 (모두 CVSS 6.3, Medium)을 발표했습니다. 이는 NousResearch의 hermes-agent toolset 핸들링의 권한 할당 및 액세스 제어 결함을 설명합니다. 특히, 이는 Unit 42가 별도로 보고한 Chinese threat actor에 의해 대량 익스플로잇을 위해 DeepSeek을 연결하도록 weaponized된 same agent 프레임워크입니다 (이전에 보고됨).
hermes-agent의 문서화된 autonomous attack 플랫폼으로서의 사용과 live mass-exploitation
get_tool_definitions in the disabled_toolsets handler incorrectly assigns privileges, and a related flaw (CVE-2026-18993) in the Memory Toolset lacks proper access controls, both remotely exploitable.
NousResearch hermes-agent ≤ 0.16.0
Upgrade to a patched hermes-agent release.
NVD CVE-2026-18976NousResearch/hermes-agent GitHub
라이브 피드에서 보기 AI 보안 및 거버넌스 관련 소식을 더 살펴보세요 — 매일 아침 업데이트.
피드 열기 →