CVE-2026-14628Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-04: 2Technical Details · 2026-07-04: 207-04
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-14628 A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the compon… https://www.cve.org/CVERecord?id=CVE-2026-14628 ----- Traducción: CVE-2026-14628 Se … http://infoflow.cloud`

    Post summary

    The text simply announces CVE-2026-14628, noting it affects the `extract_media` function in NousResearch hermes-agent, but offers no PoC, exploit details, patch, or evidence of active exploitation.

    0000034
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14628 A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the compon… https://www.cve.org/CVERecord?id=CVE-2026-14628

    Post summary

    The CVE-2026-14628 vulnerability was reported in NousResearch hermes-agent up to 2026.5.16, impacting the extract_media function, with no exploit or patch information provided.

    00000723
    57.7K followersView on X

Explore more