CVE-2026-9352: NousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosure
A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function makerunenv of the file tools/environments/local.py of the component Messaging Gateway Handler. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
nousresearch/hermes-agentfrom your environment.If the hermes-agent is not required, uninstall or disable the component until a vendor fix is available; otherwise isolate the host running it from untrusted networks.
- Compensating control
Restrict remote access to the NousResearch hermes-agent (Messaging Gateway Handler) so the vulnerable _make_run_env cannot be reached from untrusted networks. Implement firewall/ACL rules or place the service behind a VPN or management network and allow only trusted IPs/hosts to connect.
- Operational
Monitor logs and network traffic for attempts to exploit the vulnerability (public exploit available). If compromise is suspected, isolate affected hosts, perform incident response and forensic analysis, and rotate any credentials or secrets that may have been disclosed. Apply vendor updates or patches immediately when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9352?
The severity of CVE-2026-9352 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-9352?
To fix CVE-2026-9352, update the NousResearch hermes-agent to a version greater than 2026.4.23.
What type of vulnerability is CVE-2026-9352?
CVE-2026-9352 is classified as an information disclosure vulnerability.
What component of NousResearch hermes-agent is affected by CVE-2026-9352?
CVE-2026-9352 affects the Messaging Gateway Handler component specifically in the _make_run_env function of local.py.
Can CVE-2026-9352 be exploited remotely?
Yes, CVE-2026-9352 can potentially be exploited through remote manipulation.