CVE-2026-7112Disclosure

LOWCVSS 2.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-27: 2Technical Details · 2026-04-27: 104-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7112 A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.p… https://www.cve.org/CVERecord?id=CVE-2026-7112

    Post summary

    The post announces CVE-2026-7112 in NousResearch hermes-agent 0.8.0, specifying the affected function _check_auth in the API server file, without any additional technical, exploit, or mitigation details.

    00000117
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7112 Improper Authentication in NousResearch Hermes-Agent 0.8.0 API Server Key Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7112

    Post summary

    CVE-2026-7112 is reported as an improper authentication flaw in NousResearch Hermes-Agent, but the text provides no PoC, exploit code, or evidence of active exploitation.

    0000059
    4.0K followersView on X

Explore more