


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_to…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 05:01:35
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies
A remote injection vulnerability has been identified in NousResearch hermes-agent up to version 2026.4.30. The vulnerability affects the _serve_plugin_skill/skill_view function in the tools/skills_tool.py file. Attackers can exploit this vulnerability remotely through manipulation techniques. The exploit has been publicly disclosed and is available for use. Despite early notification, the vendor has not responded to the disclosure. This vulnerability allows for injection attacks that can be performed from remote locations.
Technical details
Mitigation steps:
Affected products:
NousResearch hermes-agent
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10220
https://gist.github.com/YLChen-007/9dd399c6f75b31fa741a613dfd41de08
https://vuldb.com/cve/CVE-2026-10220
https://vuldb.com/submit/822018
https://vuldb.com/vuln/367499
https://vuldb.com/vuln/367499/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
