CVE-2026-84288
Received Received - Intake

Denial of Service in NousResearch Hermes-Agent

Vulnerability report for CVE-2026-84288, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: VulDB

Description

A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nousresearch hermes-agent to 0.18.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in NousResearch hermes-agent up to version 0.18.2. It exists in the HermesACPAgent.prompt function within the acp_adapter/session.py file, specifically in the ACP Prompt Workflow component. An attacker can remotely exploit this to cause a service disruption.

Detection Guidance

This vulnerability affects the Hermes-agent component up to version 0.18.2, specifically in the ACP Prompt Workflow. To detect it, check if the vulnerable version of hermes-agent is installed by running commands like 'pip show hermes-agent' or 'dpkg -l | grep hermes-agent'. If installed, verify the version is below 0.18.3. Monitor network traffic for unusual ACP Prompt Workflow requests targeting session.py.

Impact Analysis

If you use the affected version of hermes-agent, an attacker could remotely trigger this vulnerability to make the service unavailable. This could disrupt operations relying on this component, leading to downtime or degraded performance.

Compliance Impact

This vulnerability causes a denial of service via remote manipulation of the ACP Prompt Workflow in HermesACPAgent.prompt. It does not directly impact data confidentiality or integrity but may disrupt system availability. Compliance impact depends on whether the affected system is critical to operations covered by GDPR, HIPAA, or other standards requiring availability controls.

Mitigation Strategies

Immediately update hermes-agent to a version beyond 0.18.2 if available. If no update exists, consider disabling the ACP Prompt Workflow in session.py or restricting network access to the vulnerable component until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84288. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart