CVE-2026-18773: NousResearch hermes-agent Quick run.py _check_slash_access authorization
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function checkslashaccess of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18773?
The severity of CVE-2026-18773 is classified as low with a score of 2.1.
How do I fix CVE-2026-18773?
To fix CVE-2026-18773, update to a patched version of NousResearch hermes-agent that addresses the authorization vulnerability.
What components are affected by CVE-2026-18773?
CVE-2026-18773 affects the _check_slash_access function in the gateway/run.py file of the Quick Command Handler component.
Can CVE-2026-18773 be exploited remotely?
Yes, CVE-2026-18773 can be exploited remotely due to improper authorization checks.
What is the impact of CVE-2026-18773?
The impact of CVE-2026-18773 includes the potential for unauthorized access due to incorrect authorization handling.