CVE-2026-7397Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.9.0 is able to mitigate this issue. The patch is identified as 311dac197145e19e07df68feba2cd55d896a3cd1. Upgrading the affected component is recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-29: 2Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7397 Symlink Following Vulnerability in NousResearch Hermes-Agent 0.8.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7397

    Post summary

    The text announces a symlink following vulnerability (CVE-2026-7397) affecting NousResearch Hermes-Agent 0.8.0, linking to a VulMon page for details, but offers no further exploit, patch, or mitigation information.

    0001051
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7397 A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulatio… https://www.cve.org/CVERecord?id=CVE-2026-7397

    Post summary

    Announcement of a discovered flaw in NousResearch hermes-agent 0.8.0 affecting _check_sensitive_path; no PoC, exploit, active use, or patch details provided.

    0000095
    57.3K followersView on X

Explore more