CVE-2026-82021: Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hermes Agentto a version that resolves this vulnerability.Fixed in 0.19.0 - Configuration
Update the bundled MCP catalog to reference the third-party upstream repository by a pinned commit SHA instead of a mutable branch reference to prevent supply-chain code execution.
Hermes Agent bundled MCP catalog third-party upstream repository reference (mutable branch vs pinned commit SHA) = pinned commit SHA (avoid mutable branch references)
Event History
Frequently Asked Questions
Which deployments are exposed?
Hermes Agent versions from 0.18.2 up to, but not including, 0.19.0 are affected when they install the bundled MCP catalog entry that references the third-party upstream repository.
What does an attacker need to exploit this issue?
The attacker must compromise the third-party upstream repository referenced by the catalog's mutable branch. They do not need credentials or direct access to the Hermes Agent host.
Is operator interaction required after the upstream repository is compromised?
No. Malicious code can propagate to every host that installs the affected catalog entry without further operator action.
What is the immediate remediation?
Upgrade Hermes Agent to version 0.19.0 or later, which is outside the affected version range.