hermes-agent@0.18.1

The self-improving AI agent — creates skills from experience, improves them during use, and runs anywhere

  • latest version

    0.19.0

  • first published

    2 months ago

  • latest version published

    17 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the hermes-agent package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Denial of Service (DoS)

    hermes-agent is a The self-improving AI agent — creates skills from experience, improves them during use, and runs anywhere

    Affected versions of this package are vulnerable to Denial of Service (DoS) via the _handle_webhook_request function in the Webhook Endpoint component. An attacker can cause excessive resource consumption by sending crafted requests remotely to the affected endpoint.

    How to fix Denial of Service (DoS)?

    There is no fixed version for hermes-agent.

    [0,)
    • M
    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    hermes-agent is a The self-improving AI agent — creates skills from experience, improves them during use, and runs anywhere

    Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the _compress_context function. An attacker can execute arbitrary code or inject malicious input by supplying crafted data to the affected process.

    How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')?

    A fix was pushed into the master branch but not yet published.

    [0,)