{"id":"CVE-2026-53869","aliases":["GHSA-4pqm-j46f-795x","PYSEC-2026-2510"],"url":"https://o3.security/vulnerability/CVE-2026-53869","summary":"Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints","details":"Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.","published":"2026-06-17T17:57:30.978Z","modified":"2026-08-12T03:51:36.277712926Z","cvss":null,"epss":{"score":0.00592,"percentile":0.45258,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"hermes-agent","fixedVersion":"0.16.0"}],"fix":{"url":"https://github.com/NousResearch/hermes-agent/commit/d9ec90585cf7616b5972e44cf8d92bb569fc3feb","label":"NousResearch/hermes-agent@d9ec905"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53869.json"},{"type":"ADVISORY","url":"https://github.com/NousResearch/hermes-agent/releases/tag/v2026.6.5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53869"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/hermes-agent-dns-rebinding-bypass-via-websocket-endpoints"},{"type":"REPORT","url":"https://github.com/NousResearch/hermes-agent/pull/30221"},{"type":"REPORT","url":"https://github.com/NousResearch/hermes-agent/pull/31685"},{"type":"FIX","url":"https://github.com/NousResearch/hermes-agent/commit/d9ec90585cf7616b5972e44cf8d92bb569fc3feb"},{"type":"PACKAGE","url":"https://github.com/NousResearch/hermes-agent"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.277712926Z"}}