What is CVE-2026-18976?
CVE-2026-18976 is a vulnerability found in NousResearch hermes-agent up to version 0.16.0. It affects the `get_tool_definitions` function in `agent/agent_init.py` via the `disabled_toolsets` handler, resulting in incorrect privilege assignment. The attack can be initiated remotely, and users are advised to update to the latest version.
Azərbaycanca: CVE-2026-18976 NousResearch hermes-agent 0.16.0 və əvvəlki versiyalarında aşkar edilmiş bir zəiflikdir. Bu, `agent/agent_init.py` faylındakı `get_tool_definitions` funksiyasında `disabled_toolsets` idarəedicisi vasitəsilə səhv imtiyaz təyinatına səbəb olur. Uzaqdan hücum mümkündür, istifadəçilərə proqramı ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-732
FAQ2
Which versions of NousResearch hermes-agent are affected by CVE-2026-18976?
CVE-2026-18976 affects NousResearch hermes-agent up to version 0.16.0.
In which component of hermes-agent was CVE-2026-18976 discovered?
The vulnerability was discovered in the `get_tool_definitions` function in `agent/agent_init.py` via the `disabled_toolsets` handler, resulting in incorrect privilege assignment.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.