{"id":"CVE-2026-82020","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-82020","summary":"Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential…","details":"Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.","published":"2026-08-28T20:20:14.323","modified":"2026-08-28T20:20:14.323","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/NousResearch/hermes-agent/commit/2b67e96aec2aa2abd5e94b544cda8e564c75f9f5","label":"NousResearch/hermes-agent@2b67e96"},"references":[{"type":"WEB","url":"https://github.com/NousResearch/hermes-agent/commit/2b67e96aec2aa2abd5e94b544cda8e564c75f9f5"},{"type":"WEB","url":"https://github.com/NousResearch/hermes-agent/commit/da28d5d113956dcf803d5cff552a120740a96a59"},{"type":"WEB","url":"https://github.com/NousResearch/hermes-agent/pull/45821"},{"type":"WEB","url":"https://github.com/NousResearch/hermes-agent/releases/tag/v2026.6.19"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/hermes-agent-credential-store-overwrite-via-file-write-tool"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T20:20:14.323"}}