CVE-2026-82021
Received Received - Intake

Hermes Agent MCP Catalog Supply Chain Vulnerability

Vulnerability report for CVE-2026-82021, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: VulnCheck

Description

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hermes_agent hermes_agent to 0.19.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Hermes Agent versions before 0.19.0 have a supply chain flaw in its bundled MCP catalog. The issue allows a remote attacker to run arbitrary code by compromising an upstream third-party repository that uses a mutable branch instead of a fixed commit. If the upstream repo is compromised, malicious code spreads to all systems installing that catalog entry without requiring further action from the user.

Impact Analysis

This vulnerability could allow attackers to execute malicious code on your system without your knowledge. Since the attack comes through a trusted third-party repository, it bypasses normal security checks. Systems running affected versions may face unauthorized access, data theft, or system compromise.

Mitigation Strategies

Upgrade Hermes Agent to version 0.19.0 or later to address the supply chain vulnerability in the bundled MCP catalog. Ensure all catalog entries use pinned commit SHAs instead of mutable branches to prevent arbitrary code execution from compromised upstream repositories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82021. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart