CVE-2026-82021
nicheSupply Chain Code Execution in Hermes Agent via Unpinned MCP Catalog
Hermes Agent versions prior to 0.19.0 ship a bundled MCP catalog that references third-party upstream repositories by mutable branch rather than a pinned commit SHA, meaning installed code is not verified against a known-good snapshot (CWE-494, download of code without integrity check). If an attacker compromises one of those upstream repositories, malicious code pushed there is pulled down and executed on every host that installs the affected catalog entry, with no further action required by the operator beyond having installed it. Successful exploitation yields arbitrary code execution with high impact to confidentiality, integrity, and availability, though the attack is conditioned on the attacker first gaining control of the upstream repository (reflected in the high attack-complexity rating). Any deployment running Hermes Agent before 0.19.0 that installs affected catalog entries is exposed. No public proof-of-concept exists, the issue is not in CISA's KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is currently known.
What to do: Upgrade to Hermes Agent 0.19.0 or later, which pins catalog dependencies to commit SHAs for integrity. Until upgraded, avoid installing MCP catalog entries whose upstream references a mutable branch, and audit hosts that already installed such entries for unexpected code or changes, rotating credentials if tampering is suspected. Monitor the upstream repositories referenced by the catalog for signs of compromise.
| Hermes Agent | prior to 0.19.0 (includes 0.18.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.
- Weakness
- CWE-494
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.