{"id":"CVE-2026-71963","summary":"Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection","details":"Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment including configured provider API keys.","modified":"2026-09-05T03:49:08.485762130Z","published":"2026-09-03T15:19:30.310Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71963.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.18.2"},{"last_affected":"0.21.0"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"0.18.2"},{"fixed":"0.21.0"}],"source":"DESCRIPTION"}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71963.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71963"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/hermes-agent-rce-via-git-core-fsmonitor-config-injection"},{"type":"REPORT","url":"https://github.com/NousResearch/hermes-agent/pull/101483"},{"type":"FIX","url":"https://github.com/NousResearch/hermes-agent/commit/f6234d00c5d59450adea1d7edd30ad3859375c79"},{"type":"PACKAGE","url":"https://github.com/NousResearch/hermes-agent"},{"type":"EVIDENCE","url":"https://www.manifold.security/blog/ai-coding-agents-git-hijack"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nousresearch/hermes-agent","events":[{"introduced":"0"},{"fixed":"f6234d00c5d59450adea1d7edd30ad3859375c79"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2026.8.31","v2026.8.27","v2026.8.19","v2026.8.18","v2026.8.16.2","v2026.8.16","v2026.8.13","v2026.8.3","v2026.7.30","v2026.7.20","v2026.7.7.2","v2026.7.7","v2026.7.1","v2026.6.19","v2026.6.5","v2026.5.29","v2026.5.28","v2026.5.16","v2026.5.7","v2026.4.30","v2026.4.23","v2026.4.16","v2026.4.13","v2026.4.8","v2026.4.3","v2026.3.30","v2026.3.28","v2026.3.23","v2026.3.17","v2026.3.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71963.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}