Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affecting hermes-agent package, versions [,0.18.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-HERMESAGENT-17933389
  • published10 Jul 2026
  • disclosed1 Jun 2026
  • creditUnknown

Introduced: 1 Jun 2026

CVE-2026-10222  (opens in a new tab)
CWE-74  (opens in a new tab)

How to fix?

Upgrade hermes-agent to version 0.18.0 or higher.

Overview

hermes-agent is a The self-improving AI agent — creates skills from experience, improves them during use, and runs anywhere

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in the _sanitize_env_lines function of the hermes_cli/config.py file. An attacker can execute unauthorized commands or inject malicious input by manipulating environment variable lines processed by this function. The attack can be performed remotely and may result in unauthorized access or modification of data.

CVSS Base Scores

version 4.0
version 3.1