CVE-2026-9366: NousResearch hermes-agent prompt_builder.py _scan_context_content injection

Published May 24, 2026
·
Updated

A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function scancontextcontent of the file agent/promptbuilder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
NousResearch hermes-agent=2026.4.23

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove NousResearch hermes-agent 2026.4.23 from your environment.

    If the hermes-agent instance (NousResearch hermes-agent 2026.4.23) is not required, uninstall or remove it from affected systems until a vendor-provided fix is available.

  2. Compensating control

    Isolate or block network access to hosts running NousResearch hermes-agent 2026.4.23 (e.g., firewall/ACL rules, network segmentation) to prevent remote exploitation. Restrict access to management interfaces to trusted IPs only.

  3. Compensating control

    Deploy detection controls (IDS/IPS, host-based monitoring, WAF rules) to detect and/or block exploitation attempts targeting the agent, and increase logging/alerting for relevant indicators.

  4. Operational

    Treat systems running NousResearch hermes-agent 2026.4.23 as potentially compromised given a publicly available exploit: perform forensic review of logs, investigate for indicators of compromise, and remediate or rebuild affected systems as appropriate.

Event History

May 24, 2026
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Apr 28, 58520
Event
via FIRST·04:18 PM

Frequently Asked Questions

1

What is the risk level of CVE-2026-9366?

The risk level of CVE-2026-9366 is classified as high with a severity score of 7.3.

2

What type of attack can exploit CVE-2026-9366?

CVE-2026-9366 can be exploited through remote injection attacks.

3

Where is the vulnerability CVE-2026-9366 located in the software?

CVE-2026-9366 is located in the function _scan_context_content of the file agent/prompt_builder.py in NousResearch hermes-agent.

4

Is the exploit for CVE-2026-9366 publicly available?

Yes, the exploit for CVE-2026-9366 has been made public.

5

How can I mitigate CVE-2026-9366?

To mitigate CVE-2026-9366, ensure you update to the latest version of NousResearch hermes-agent that addresses this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203