CVE-2026-82020 HIGH

CVE-2026-82020: Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool

Vendor Nousresearch
Product hermes-agent
Weakness CWE-552 · Files accessible externally
Published August 28, 2026
Last update August 29, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 29, 2026 Record updated