What is CVE-2026-18993?
An improper access control vulnerability was found in the Memory Toolset component of NousResearch hermes-agent versions up to 0.16.0, specifically in the `model_tools.py` file. This flaw can be exploited remotely, potentially allowing unauthorized access. Users are advised to upgrade to the latest version immediately.
Azərbaycanca: NousResearch hermes-agent-in 0.16.0 və daha əvvəlki versiyalarında `model_tools.py` faylındakı Memory Toolset komponentində uzaqdan icra oluna bilən səlahiyyət yoxlaması zəifliyi aşkarlanıb. Bu, təcavüzkara sistemə icazəsiz giriş imkanı verə bilər. İstifadəçilərə dərhal ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
In which component of NousResearch hermes-agent was CVE-2026-18993 discovered?
CVE-2026-18993 was discovered in the Memory Toolset component within the `model_tools.py` file of hermes-agent versions up to 0.16.0.
What is recommended to protect against CVE-2026-18993?
Users are advised to upgrade to the latest version immediately to protect against CVE-2026-18993.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.