A AegiFlow
MEDIUMCVSS 5.5EPSS 0.3%

CVE-2026-10221

CVE-2026-10221 updated by NVD

Published
2026-06-01
Modified
2026-07-28
EPSS percentile
23%
Sources
github-advisory, nvd

Summary

A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIhermes-agent

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.