CVE-2026-7396: NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal
A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7396?
CVE-2026-7396 is classified as a medium severity vulnerability due to its potential for path traversal exploitation.
How do I fix CVE-2026-7396?
To fix CVE-2026-7396, upgrade the NousResearch hermes-agent to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-7396?
CVE-2026-7396 affects NousResearch hermes-agent version 0.8.0 specifically.
What type of vulnerability is CVE-2026-7396?
CVE-2026-7396 is a path traversal vulnerability in the WeChat Work Platform Adapter component.
What can an attacker achieve with CVE-2026-7396?
An attacker exploiting CVE-2026-7396 can potentially access files outside the intended directory structure.