云虫漏洞库

CVE-2026-82020 - Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access. - 漏洞详情

漏洞编号:CVE-2026-82020

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-82020

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-552

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.

相关链接

相关漏洞

« 返回首页