What is CVE-2026-17432?
This vulnerability involves improper handling of the `contactId` argument in the SimpleX Gateway Authorization component of NousResearch hermes-agent 2026.6.5. It could allow unauthorized manipulation of agent functionalities; users should apply patches provided by the vendor.
Azərbaycanca: Bu boşluq NousResearch hermes-agent 2026.6.5 versiyasında, SimpleX Gateway Authorization komponentində `contactId` arqumentinin düzgün idarə olunmaması ilə bağlıdır. Bu, təsdiqlənməmiş istifadəçilərə agentin funksiyalarına müdaxilə etməyə imkan verə bilər; məhsul sahibləri yamaq üçün təchizatçı tərəfindən verilən yeniləmələri tətbiq etməlidir.
Related CVEs
link basis: shared vendor: NousResearch
FAQ2
Which component in NousResearch hermes-agent 2026.6.5 is affected by the improper handling of the `contactId` argument?
The SimpleX Gateway Authorization component.
What could an unauthenticated user achieve by exploiting this vulnerability?
They could manipulate the agent's functionalities.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.