CVE-2026-18976: NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function gettooldefinitions of the file agent/agentinit.py of the component disabledtoolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or remove the affected disabled_toolsets toolsets implementation so that get_tool_definitions in agent/agent_init.py cannot be manipulated to cause incorrect privilege assignment (issue states: disabled_toolsets agent_init.py get_tool_definitions).
NousResearch hermes-agent (disabled_toolsets Handler) agent/agent_init.py get_tool_definitions privileges assignment = prevent incorrect privilege assignment by disabling/manipulation of get_tool_definitions in disabled_toolsets agent_init.py - Compensating control
Since the attack may be initiated remotely, restrict network access to hermes-agent endpoints (e.g., management/API ports used by hermes-agent) to trusted IPs only (firewall/ACL) to limit exposure while remediating.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18976?
CVE-2026-18976 has a medium severity score of 6.3.
What components are affected by CVE-2026-18976?
CVE-2026-18976 affects the function get_tool_definitions in the disabled_toolsets Handler of NousResearch hermes-agent up to version 0.16.0.
How can an attacker exploit CVE-2026-18976?
An attacker can exploit CVE-2026-18976 remotely to manipulate privilege assignments.
What impact does CVE-2026-18976 have on system privileges?
CVE-2026-18976 leads to incorrect privilege assignment, potentially allowing unauthorized access.
How can users protect against CVE-2026-18976?
Users should upgrade to a patched version of NousResearch hermes-agent to mitigate CVE-2026-18976.