CVE-2026-14625 Details
Description
A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in NousResearch Hermes-Agent versions through 0.15.2, specifically within the TUI gateway's command dispatch system. The issue arises because the shell execution functions bypass the integrated security scanner, 'tirith', allowing unfiltered execution of shell commands. This flaw can be exploited remotely, leading to potential unauthorized code execution on the host system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 4, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/YLChen-007/3b11589740dcf16b152b0929e1b3d024 | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-14625 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/845595 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/376141 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/376141/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NousResearch hermes-agent | <= 0.15.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 4, 2026 | New CVE Received | [email protected] |
Volerion