CVE-2026-53870 PUBLISHED

Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files

Assigner: VulnCheck
Reserved: 10.06.2026 Published: 17.06.2026 Updated: 17.06.2026

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history, tool payloads, prompts, and per-route HMAC secrets.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor NousResearch
Product hermes-agent
Versions Default: unaffected
  • affected from 0 to 0.16.0 (excl.)
  • Version 0.16.0 is unaffected

Credits

  • Chia Min Jun Lennon finder

References

Problem Types

  • Incorrect Default Permissions CWE