CVE-2026-9354: NousResearch hermes-agent Slack Agent/Mattermost Agent escape output
A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost Agent. The manipulation of the argument formatmessage results in escaping of output. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
NousResearch hermes-agentfrom your environment.Uninstall NousResearch hermes-agent if Slack/Mattermost integration is not required or until a vendor-provided fix is available.
- Configuration
If possible, disable the Slack Agent / Mattermost Agent or disable processing of the format_message argument in hermes-agent configuration to prevent remote manipulation of format_message that leads to escaped output.
NousResearch hermes-agent (Slack Agent/Mattermost Agent) Slack Agent/Mattermost Agent / format_message processing = disabled - Compensating control
Restrict network access to the hermes-agent: block or firewall inbound traffic to the agent's ports, allow only trusted hosts to communicate with it, and isolate the agent from networks where untrusted users can send messages.
- Operational
Monitor logs and message handling related to format_message for signs of exploitation, and perform incident response if any indicators of compromise are found (investigate, contain, and remediate).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9354?
The severity of CVE-2026-9354 is medium with a score of 6.5.
How do I fix CVE-2026-9354?
To fix CVE-2026-9354, update the NousResearch hermes-agent to version 2026.4.17 or later.
What component is affected by CVE-2026-9354?
CVE-2026-9354 affects the Slack Agent/Mattermost Agent component of NousResearch hermes-agent.
Can the attack for CVE-2026-9354 be executed remotely?
Yes, the attack for CVE-2026-9354 can be executed remotely.
What type of vulnerability is CVE-2026-9354?
CVE-2026-9354 is an output escaping vulnerability resulting from improper handling of the format_message argument.