Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
1.9

CVE-2026-10548: NousResearch hermes-agent Credential Pool Authentication Bypass

CVE-2026-10548
Summary

A security issue in NousResearch hermes-agent allows an attacker with local access to bypass authentication checks. This could potentially allow unauthorized access to sensitive data. NousResearch has not responded to the vulnerability disclosure, so users should consider updating to a patched version.

Original title
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the c...
Original description
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 4.3
nvd CVSS3.1 5.3
nvd CVSS4.0 1.9
Vulnerability type
CWE-287 Improper Authentication
Published: 2 Jun 2026 · Updated: 2 Jun 2026 · First seen: 2 Jun 2026