CVE-2026-18993 Details
Description
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used.
A vulnerability in NousResearch Hermes-Agent versions through 0.16.0 allows memory-provider tools to be called even when the 'memory' toolset is disabled. This bypass occurs because, after the initial filtering of tools based on the user's preferences, the agent reintroduces memory-provider tools without reapplying the deny policy. As a result, tools like 'fact_store' and 'fact_feedback' remain visible and executable, leading to unauthorized persistence of memory-related actions.
Users can update to Hermes-Agent version 0.20.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/NousResearch/hermes-agent/ | [email protected] | Source CodeVendor |
| https://github.com/NousResearch/hermes-agent/issues/46171 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/NousResearch/hermes-agent/issues/48181 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/NousResearch/hermes-agent/pull/46185 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-18993 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/862610 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/386377 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/386377/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NousResearch hermes-agent | <= 0.16.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion