В Hermes-агенте NousResearch 2026.6.5 обнаружена уязвимость. Этой уязвимости подвержена неизвестная функциональность файла hermes-agent/plugins/platforms/simplex/adapter.py компонента SimpleX Gateway Authorization. Манипулирование аргументом contactId приводит к неправильному управлению доступом.
Атака может быть запущена удаленно. Эта атака связана с высоким уровнем сложности. Эксплуатация представляется сложной.
Эксплойт теперь общедоступен и может быть использован. Патч идентифицируется как 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Чтобы решить эту проблему, рекомендуется применить патч.
Показать оригинальное описание (EN)
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue.
Характеристики атаки
Последствия
Строка CVSS v4.0