NousResearch hermes-agent
- <= 2026.4.30
A vulnerability exists in NousResearch Hermes-Agent versions through 2026.4.30, specifically within the live streaming filters of the GatewayStreamConsumer component. The issue arises from improper handling of case sensitivity in reasoning tags, allowing mixed-case tags to bypass filters and leak hidden content, such as system prompts and internal logic, to users. This vulnerability can be exploited remotely, with a high complexity and difficulty of exploitation.
Exploitation of this vulnerability leads to unauthorized information disclosure, allowing hidden reasoning content, including system prompts and internal decision-making processes, to be exposed during live streaming interactions.
The vulnerability can be reproduced by sending messages that include mixed-case reasoning tags, such as '<THINK>' or '<THOUGHT>'. These tags will bypass the case-sensitive filtering and be displayed to the user. This can be automated with a script that simulates LLM response chunks containing the uppercase tags, verifying that they leak through the filter while lowercase tags are correctly filtered.
Users can manually update to the latest version of Hermes-Agent, where this vulnerability has been addressed. Instructions for updating are available in the Hermes-Agent documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.