Sceawere

Vulnerability Detail

CVE-2026-84288UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hermes-agent ACP Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
NousResearch
Product
hermes-agent
Attack Type
Denial of Service
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-01T22:17:18.647Z",
  "pubdate": "2026-09-01T22:17:18.647Z",
  "executiveSummary": "A denial of service vulnerability exists within the ACP Prompt Workflow component of the NousResearch hermes-agent library, specifically affecting versions up to 0.18.2.\nThe vulnerability resides within the HermesACPAgent.prompt function located in the acp_adapter/session.py file.\nThis flaw allows a remote, unauthenticated attacker to induce a service disruption by sending specially crafted input to the affected function.\nThe vulnerability is currently public, and given the lack of vendor response, the risk remains unmitigated for deployments utilizing these specific versions.\nSuccessful exploitation results in the exhaustion of system resources or application termination, effectively rendering the agent service unavailable for legitimate users.\nOrganizations using hermes-agent should implement immediate compensating controls or restrict access to the affected components to mitigate potential service availability risks.",
  "technicalDetails": "The vulnerability is located in the ACP Prompt Workflow component, specifically within the HermesACPAgent.prompt function defined in acp_adapter/session.py.\nThe root cause of the denial of service appears to be improper handling or sanitization of input data passed to the prompt method, which triggers an unhandled exception or resource exhaustion condition during the execution flow of the agent's workflow.\nBecause the function is designed to process external prompt inputs, the vulnerability is reachable from remote network segments without requiring prior authentication or specific privilege levels.\nThe attack flow begins when an attacker sends a malicious payload formatted to interact with the ACP Prompt interface. Upon reaching the HermesACPAgent.prompt function, the input bypasses existing validation checks or interacts with downstream dependencies in a way that causes the process to hang, crash, or consume excessive CPU/memory resources.\nAs the exploit is public, the attack vector is straightforward; an attacker can transmit a crafted request that triggers the vulnerable code path. The lack of robust exception handling within acp_adapter/session.py ensures that the error state propagates to the top-level application, leading to the termination of the agent's session or the service process itself.\nAffected versions include all releases of hermes-agent up to and including 0.18.2. Since the logic is embedded within the core adapter, all deployments relying on this component are susceptible to this remote denial of service vector.\nPost-exploitation, the service remains unavailable until manual intervention, such as a process restart, is performed. The absence of vendor-supplied patches necessitates that security teams focus on input filtering and boundary protection to prevent malicious payloads from reaching the vulnerable function."
}
CVE-2026-84288: Hermes-agent ACP Denial of Service (MEDIUM Severity, CVSS: 4.3) - Sceawere