Ghostwire

CVE-2026-7113: A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of...

MEDIUM CVSS 5.6 EPSS 0.07% Exploit Available 1 PoC

Published: April 27, 2026 | Last Modified: April 27, 2026

Description

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitation is known to be difficult. The exploit has been made public and could be used. The project was informed of the problem early through a pull request but has not reacted yet.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.07% (22th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (1)

Security Coverage (1 articles)

References