Back

HIGH

Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection

Published Sep 3, 2026

Description

Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment including configured provider API keys.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Sep 3, 2026
Updated Sep 3, 2026
Reserved Aug 8, 2026

CISA Vulnrichment

Updated Sep 3, 2026

NVD

Status Deferred
Modified Sep 8, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Sep 3, 2026
Updated Sep 3, 2026

GitHub

No data