Vulnerability Description
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/NousResearch/hermes-agent/commit/9df5f879b4a5925c0f8f947e7e16
- https://github.com/NousResearch/hermes-agent/pull/64463
- https://github.com/NousResearch/hermes-agent/releases/tag/v2026.7.20
- https://www.vulncheck.com/advisories/hermes-agent-mcp-catalog-supply-chain-rce-v
FAQ
What is CVE-2026-82021?
CVE-2026-82021 is a vulnerability with a CVSS score of 8.3 (HIGH). Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repo...
How severe is CVE-2026-82021?
CVE-2026-82021 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82021?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.