CVE-2026-9366: NousResearch hermes-agent prompt_builder.py _scan_context_content injection
A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function scancontextcontent of the file agent/promptbuilder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
NousResearch hermes-agent 2026.4.23from your environment.If the hermes-agent instance (NousResearch hermes-agent 2026.4.23) is not required, uninstall or remove it from affected systems until a vendor-provided fix is available.
- Compensating control
Isolate or block network access to hosts running NousResearch hermes-agent 2026.4.23 (e.g., firewall/ACL rules, network segmentation) to prevent remote exploitation. Restrict access to management interfaces to trusted IPs only.
- Compensating control
Deploy detection controls (IDS/IPS, host-based monitoring, WAF rules) to detect and/or block exploitation attempts targeting the agent, and increase logging/alerting for relevant indicators.
- Operational
Treat systems running NousResearch hermes-agent 2026.4.23 as potentially compromised given a publicly available exploit: perform forensic review of logs, investigate for indicators of compromise, and remediate or rebuild affected systems as appropriate.
Event History
Frequently Asked Questions
What is the risk level of CVE-2026-9366?
The risk level of CVE-2026-9366 is classified as high with a severity score of 7.3.
What type of attack can exploit CVE-2026-9366?
CVE-2026-9366 can be exploited through remote injection attacks.
Where is the vulnerability CVE-2026-9366 located in the software?
CVE-2026-9366 is located in the function _scan_context_content of the file agent/prompt_builder.py in NousResearch hermes-agent.
Is the exploit for CVE-2026-9366 publicly available?
Yes, the exploit for CVE-2026-9366 has been made public.
How can I mitigate CVE-2026-9366?
To mitigate CVE-2026-9366, ensure you update to the latest version of NousResearch hermes-agent that addresses this vulnerability.