PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9350 NousResearch CVE debrief

A missing authorization vulnerability exists in NousResearch hermes-agent up to version 2026.4.16, specifically within the `check_all_command_guards` function in `tools/approval.py` of the Batch Runner component. The flaw allows remote attackers to bypass authorization controls, potentially enabling unauthorized command execution. The vulnerability has a CVSS 4.0 score of 5.5 (MEDIUM severity) with an attack vector of network-accessible, low attack complexity, and no required privileges or user interaction. The exploit has been publicly disclosed and is available, increasing the risk of active exploitation. The vendor was contacted prior to disclosure but did not respond.

Vendor
NousResearch
Product
hermes-agent
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-24
Original CVE updated
2026-07-23
Advisory published
2026-05-24
Advisory updated
2026-07-23

Who should care

Organizations running NousResearch hermes-agent versions up to 2026.4.16 with the Batch Runner component enabled; security teams managing AI/ML agent infrastructure; DevOps teams deploying automated agent workflows.

Technical summary

The vulnerability resides in the `check_all_command_guards` function within `tools/approval.py` of the hermes-agent Batch Runner component. The function fails to properly enforce authorization checks, allowing remote attackers to submit commands without adequate authentication or authorization validation. The flaw is network-exploitable with low complexity and requires no privileges or user interaction. The publicly available exploit demonstrates the bypass mechanism.

Defensive priority

medium

Recommended defensive actions

  • Review and update hermes-agent to a version newer than 2026.4.16 if available, or apply vendor-provided patches
  • Implement additional authorization controls at the infrastructure level to compensate for the missing application-level guards
  • Monitor for anomalous command execution patterns in Batch Runner deployments, particularly unauthorized or unexpected command sequences
  • Restrict network access to hermes-agent Batch Runner instances to trusted administrative hosts only
  • Audit `tools/approval.py` for custom patches or workarounds if vendor patches are unavailable
  • Review logs for evidence of exploitation attempts targeting the `check_all_command_guards` function

Evidence notes

Vulnerability identified in `tools/approval.py` within the `check_all_command_guards` function. CWE-862 (Missing Authorization) and CWE-863 (Incorrect Authorization) classified. CVSS 4.0 vector: AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/E:P. Public exploit available via referenced gist.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9350 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9350

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9350 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9350

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.