Vibe Coding
CVE-2026-71963: Hermes Agent RCE stayed open through six unanswered vendor contacts
NVD published CVE-2026-71963 on 2026-09-03 for Hermes Agent 0.18.2 through 0.21.0: a malicious repository's .git/config core.fsmonitor value executes in the user's process context as soon as the user opens the repo and sends any message, exposing the full environment including configured provider API keys. The fix is commit f6234d0. The CVE was assigned only after the vendor did not respond across six contact attempts, which is why this one has an ID while the Claude Code, Cursor, Qwen Code and Grok Build variants of the same bug do not.
Source
↳ Follow the thread