What is CVE-2026-18774?
A Server-Side Request Forgery (SSRF) vulnerability was found in the `save_url_image` function in `agent/image_gen_provider.py` of NousResearch hermes-agent up to version 0.16.0. This flaw allows a remote attacker to send unauthorized requests to internal network resources from the affected server. Upgrading to the latest version is recommended for affected systems.
Azərbaycanca: NousResearch hermes-agent proqramının 0.16.0-a qədər versiyalarında `agent/image_gen_provider.py` faylındakı `save_url_image` funksiyasında Server-Side Request Forgery (SSRF) zəifliyi aşkar edilib. Bu boşluq uzaqdan hücum edən şəxsə serveri yönləndirərək daxili şəbəkə resurslarına icazəsiz sorğular göndərməyə imkan verir. Təsirlənən sistemlərdə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: NousResearch
FAQ2
What is the type of vulnerability identified as CVE-2026-18774 in the NousResearch hermes-agent?
CVE-2026-18774 is a Server-Side Request Forgery (SSRF) vulnerability found in the `save_url_image` function within the `agent/image_gen_provider.py` file.
What is the recommended security measure for CVE-2026-18774?
Upgrading to the latest version is recommended for affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.