CVE-2026-7396 PUBLISHED

NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal

Assigner: VulDB
Reserved: 29.04.2026 Published: 29.04.2026 Updated: 29.04.2026

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor NousResearch
Product hermes-agent
Versions
  • Version 0.8.0 is affected

Credits

  • Yu_Bao (VulDB User) reporter

References

Problem Types

  • Path Traversal CWE