Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment including configured provider API keys. Join the discussion | CVE Database V5 | 09/03/2026, 15:19:30 UTC Added: 09/03/2026, 15:22:58 UTC |
0 Hermes Agent versions prior to 0.19.0 contain a supply chain vulnerability in their bundled MCP catalog. This flaw allows remote attackers to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch instead of a pinned commit SHA. Exploitation requires no further operator action once the malicious code is propagated through the affected catalog entry. Join the discussion | CVE Database V5 | 08/28/2026, 18:50:38 UTC Added: 08/28/2026, 19:40:03 UTC |
0 Hermes Agent versions 0.16.0 up to but not including 0.17.0 contain a vulnerability where attackers can bypass path restrictions to overwrite the credential store file auth.json. This improper path restriction allows crafted messages to direct file-write operations to sensitive files, enabling credential tampering or unauthorized access. The vulnerability has a high severity score of 7.6 and requires user interaction but no privileges. No official patch or remediation guidance is currently confirmed. Join the discussion | CVE Database V5 | 08/28/2026, 18:47:06 UTC Added: 08/28/2026, 19:40:02 UTC |
A vulnerability exists in NousResearch hermes-agent up to version 0.16.0 in the Memory Toolset component, specifically in the hermes-agent/model_tools.py file. This issue involves improper access controls that can be exploited remotely. The vulnerability has a CVSS 3.1 score of 6.3, indicating a medium severity level. Exploit code for this vulnerability is publicly available, but there are no known exploits observed in the wild. No patch or official fix information is currently provided. Join the discussion | GCVE Database | 08/06/2026, 03:45:10 UTC Added: 08/06/2026, 18:17:14 UTC |
CVE-2026-18993 is a medium severity vulnerability in NousResearch hermes-agent up to version 0.16.0. It involves improper access controls in the Memory Toolset component, specifically in the hermes-agent/model_tools.py file. The vulnerability allows remote attackers to exploit the issue without user interaction or elevated privileges. Exploit code is publicly available, but no official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 08/06/2026, 03:45:10 UTC Added: 08/06/2026, 04:26:48 UTC |
A vulnerability in NousResearch hermes-agent up to version 0.16.0 allows remote attackers to cause incorrect privilege assignment via the get_tool_definitions function in agent/agent_init.py. This issue relates to improper handling in the disabled_toolsets Handler component. The vulnerability has a CVSS score of 6.3 and has been publicly disclosed, but no known exploits are currently observed in the wild. Join the discussion | GCVE Database | 08/06/2026, 01:45:12 UTC Added: 08/06/2026, 18:17:15 UTC |
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 08/04/2026, 16:00:11 UTC Added: 08/04/2026, 16:28:46 UTC |
CVE-2026-18773 is a medium severity vulnerability in NousResearch hermes-agent up to version 2026.6.5. It involves incorrect authorization in the _check_slash_access function within the Quick Command Handler component. The vulnerability can be exploited remotely without user interaction. Public exploit code is available, and the vendor has not responded to disclosure attempts. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/04/2026, 15:00:09 UTC Added: 08/04/2026, 15:42:02 UTC |
CVE-2026-17432 is a low-severity vulnerability in NousResearch hermes-agent version 2026.6.5 involving improper access controls in the SimpleX Gateway Authorization component. The issue arises from manipulation of the contactId argument in the file hermes-agent/plugins/platforms/simplex/adapter.py. Exploitation requires high complexity and no privileges, but the exploit is publicly available. A patch identified by commit 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3 is advised to resolve the issue. Join the discussion | CVE Database V5 | 07/26/2026, 00:15:11 UTC Added: 07/26/2026, 01:08:20 UTC |
A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance. Join the discussion | CVE Database V5 | 07/09/2026, 23:45:10 UTC Added: 07/10/2026, 00:18:09 UTC |
Showing 1 to 10 of 29 results