CVE-2026-7396

medium

Description

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

References

https://vuldb.com/vuln/360120/cti

https://vuldb.com/vuln/360120

https://vuldb.com/submit/803269

https://github.com/bugmaker2/hermes-agent/issues/29

https://github.com/NousResearch/hermes-agent/issues/8733

https://github.com/NousResearch/hermes-agent/

Details

Source: Mitre, NVD

Published: 2026-04-29

Updated: 2026-04-29

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00048