ZeroHour

CVE-2026-82020

niche

Improper Path Restriction in Hermes Agent Enables Credential Store Overwrite

CVSS 4.0
7.6 high
EPSS
<1%p26
Published
()
Modified
AI analysis

Hermes Agent 0.16.0 prior to 0.17.0 fails to properly restrict the paths its file-write tooling can touch, allowing attackers to bypass the sensitive-path guards that were supposed to exclude the auth.json credential store from writes. An attacker who can influence the content of messages ingested by the agent can craft malicious message content that directs the agent's file-write tooling to overwrite the credential store without triggering any path-based protection. Successful exploitation enables credential tampering — replacing or corrupting stored credentials — which can lead to unauthorized access. Only deployments running affected Hermes Agent versions that ingest content from sources an attacker can influence are exposed. No public proof-of-concept, KEV listing, or known exploitation exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Upgrade to Hermes Agent 0.17.0 or later, which restores proper sensitive-path protection for the auth.json credential store. Until upgraded, limit the agent's ingestion of untrusted message content and monitor auth.json for unexpected modifications. If auth.json was changed without a legitimate reason, rotate the stored credentials and check for signs of unauthorized access.

Affected
Hermes Agent0.16.0 prior to 0.17.0 (fixed in 0.17.0)
Estimated exposure
nichelikely low thousands of deployments at most (early-stage 0.x agent tool; no published install metrics) — No public install-count or telemetry data exists for Hermes Agent, and its 0.x versioning indicates an early-stage project with a small developer/enthusiast deployment base, so this is a rough order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.

Weakness
CWE-552
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.