


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_to…
Published:
31 mei 2026 om 22:00:00
Alert date:
1 juni 2026 om 16:08:13
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies
A remote injection vulnerability (CVE-2026-10220) was discovered in NousResearch hermes-agent up to version 2026.4.30. The vulnerability affects the _serve_plugin_skill/skill_view function in the tools/skills_tool.py file. The attack can be performed remotely through manipulation that leads to injection. The exploit has been publicly disclosed and is available for use. The vendor was contacted about the vulnerability but did not respond.
Technical details
Mitigation steps:
Affected products:
NousResearch hermes-agent
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10220
https://gist.github.com/YLChen-007/9dd399c6f75b31fa741a613dfd41de08
https://vuldb.com/cve/CVE-2026-10220
https://vuldb.com/submit/822018
https://vuldb.com/vuln/367499
https://vuldb.com/vuln/367499/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
