Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection
Published Sep 3, 2026
8.6
HIGHCVSS 4.0
EPSS 0.86%
Description
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment including configured provider API keys.
Affected products
-
Affected
- ≥ 0.18.2, ≤ 0.21.0
-
Unaffected
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| NousResearch | Hermes-Agent | affected | Affected
|
| NousResearch | Hermes-Agent | affected | Unaffected |
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70526 Advisory
- https://github.com/NousResearch/hermes-agent/commit/f6234d00c5d59450adea1d7edd30ad3859375c79 patch
- https://github.com/NousResearch/hermes-agent/pull/101483 issue-tracking
- https://www.manifold.security/blog/ai-coding-agents-git-hijack technical-descriptionexploit
- https://www.vulncheck.com/advisories/hermes-agent-rce-via-git-core-fsmonitor-config-injection third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70526 | Advisory | |
| https://github.com/NousResearch/hermes-agent/commit/f6234d00c5d59450adea1d7edd30ad3859375c79 | patch | |
| https://github.com/NousResearch/hermes-agent/pull/101483 | issue-tracking | |
| https://www.manifold.security/blog/ai-coding-agents-git-hijack | technical-descriptionexploit | |
| https://www.vulncheck.com/advisories/hermes-agent-rce-via-git-core-fsmonitor-config-injection | third-party-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data