云虫漏洞库

CVE-2026-82021 - Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator. - 漏洞详情

漏洞编号:CVE-2026-82021

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-82021

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-494

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.

相关链接

相关漏洞

« 返回首页