What is CVE-2026-18773?
An incorrect authorization vulnerability has been identified in the `_check_slash_access` function within `gateway/run.py` of NousResearch hermes-agent, affecting versions up to 2026.6.5. The flaw in the Quick Command Handler component allows remote attackers to perform unauthorized operations. Updating to the latest version is recommended for affected systems.
Azərbaycanca: NousResearch hermes-agent proqramının 2026.6.5 versiyasına qədər olan versiyalarında `gateway/run.py` faylındakı `_check_slash_access` funksiyasında səhv avtorizasiya zəifliyi aşkar edilib. Bu, uzaqdan hücumçuya Quick Command Handler komponenti vasitəsilə icazəsiz əməliyyatlar aparmağa imkan verir. Təsirlənən sistemlərdə proqramın ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
In which file is the vulnerability that leads to unauthorized operations in NousResearch hermes-agent located?
The vulnerability is located in the `_check_slash_access` function within the `gateway/run.py` file.
Which versions are affected by the CVE-2026-18773 vulnerability?
Versions of NousResearch hermes-agent up to 2026.6.5 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.