Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. copyImageFromUrl() entry point no longer reachable on current main. That function did exist at v2026.8.3 but was removed by v2026.8.19. The modern copy-image path is Electron-native event.sender.copyImageAt(). | |
| Title | NousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resources | |
| First Time appeared |
Nousresearch
Nousresearch hermes-agent |
|
| Weaknesses | CWE-400 CWE-770 |
|
| CPEs | cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nousresearch
Nousresearch hermes-agent |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-03T13:04:33.914Z
Reserved: 2026-09-03T06:47:17.090Z
Link: CVE-2026-85107
Updated: 2026-09-03T13:04:31.189Z
Status : Deferred
Published: 2026-09-03T13:06:21.603
Modified: 2026-09-03T17:25:25.113
Link: CVE-2026-85107
No data.
OpenCVE Enrichment
Updated: 2026-09-03T15:15:05Z