CVE-2026-15311General

LOWCVSS 2.0 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-10: 3Technical Details · 2026-07-10: 107-10
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-15311 A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gate… https://www.cve.org/CVERecord?id=CVE-2026-15311

    Post summary

    The text merely announces CVE-2026-15311 with a brief mention of the affected function, providing no further technical details or actionable information.

    00010727
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-15311 A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gate… https://www.cve.org/CVERecord?id=CVE-2026-15311 ----- Traducción: CVE-2026-15311 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑15311, noting it affects the MatrixAdapter._markdown_to_html function in NousResearch hermes-agent, but offers no evidence of exploitation, patches, or a PoC.

    0000052
    91 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-15311](https://github.com/NousResearch/hermes-agent/) A vulnerability was identified in... https://github.com/NousResearch/hermes-agent/ #ZeroDay #PatchManagement #Vulnerability

    Post summary

    A brief notice announces CVE‑2026‑15311 and links to its GitHub repository, but provides no substantive technical or exploit information.

    0000046
    10 followersView on X

Explore more