Vibe Coding
Hermes Agent Shipped an MCP Catalog Pinned to a Mutable Branch, Turning Any Upstream Compromise Into RCE (CVE-2026-82021, 9.0)
Published 2026-08-28 at 20:20 UTC, CVE-2026-82021 covers Hermes Agent 0.18.2 through 0.19.0, where the bundled MCP catalog referenced a third-party upstream repository by mutable branch rather than a pinned commit SHA. An attacker who compromises that upstream propagates code to every host installing the catalog entry with no operator action. The same batch includes CVE-2026-82020 (7.6), where attacker-influenced ingested message content could overwrite the credential store by bypassing sensitive-path guards that excluded `auth.json`.
Source
↳ Follow the thread