CVE-2026-84289
Received Received - Intake

Uncontrolled Memory Allocation in Hermes-Agent MCP Tool

Vulnerability report for CVE-2026-84289, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: VulDB

Description

A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulation results in uncontrolled memory allocation. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nousresearch hermes-agent to 0.18.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled memory allocation issue in the function list_tools of the file tools/mcp_tool.py in the NousResearch hermes-agent software up to version 0.18.2. It allows remote attackers to trigger excessive memory usage, potentially leading to system instability or crashes.

Impact Analysis

The vulnerability could cause denial-of-service conditions by consuming excessive memory, leading to application crashes or degraded performance. Since it is remotely exploitable, attackers could target systems running the vulnerable software without needing local access.

Mitigation Strategies

Upgrade hermes-agent to a version beyond 0.18.2 to address the uncontrolled memory allocation issue in the MCP Tool component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84289. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart