What is CVE-2026-18775?
A Server-Side Request Forgery (SSRF) vulnerability has been discovered in the browser_snapshot function in tools/browser_tool.py of NousResearch hermes-agent up to version 0.16.0. This remotely exploitable flaw could allow attackers to make unauthorized server-side requests. Users are advised to upgrade to the latest version immediately.
Azərbaycanca: NousResearch hermes-agent-in 0.16.0 versiyasına qədər olan versiyalarında browser_tool.py faylındakı browser_snapshot funksiyasında Server-Side Request Forgery (SSRF) zəifliyi aşkar edilmişdir. Bu uzaqdan həyata keçirilə bilən hücum, təcavüzkara server tərəfindən icazəsiz sorğular göndərməyə imkan yarada bilər. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: NousResearch
FAQ1
In which function of NousResearch hermes-agent was the SSRF vulnerability discovered?
The SSRF vulnerability was discovered in the browser_snapshot function within the browser_tool.py file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.