CVE-2026-9369: NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function discoverdashboardplugins of the file hermescli/webserver.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMESENABLEPROJECTPLUGINS results in incorrect comparison. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9369?
The severity of CVE-2026-9369 is medium, rated at 5.3.
How do I fix CVE-2026-9369?
To fix CVE-2026-9369, update to the latest version of NousResearch hermes-agent that addresses this vulnerability.
What component is affected by CVE-2026-9369?
CVE-2026-9369 affects the CLI web-dashboard interface within the NousResearch hermes-agent software.
How does CVE-2026-9369 exploit the HERMES_ENABLE_PROJECT_PLUGINS argument?
CVE-2026-9369 exploits the HERMES_ENABLE_PROJECT_PLUGINS argument by allowing manipulation that can lead to incorrect behavior in the function _discover_dashboard_plugins.
What is the impact of CVE-2026-9369 on data confidentiality?
The impact of CVE-2026-9369 on data confidentiality is low, but it can lead to potential data exposure if exploited.