AEV-2026-0018
Hermes Agent's context gathering git status let a repository run a command, unresolved after the vendor did not respond (CVE-2026-71963)
Hermes Agent's own git status call for repository context let a repository's core.fsmonitor setting execute an attacker named command, confirmed by Manifold Security on two separate versions across July and September 2026 with no fix shipped. VulnCheck assigned CVE-2026-71963 after Nous Research reportedly did not respond to six separate contact attempts; the NousResearch hermes-agent repository carries no published security advisory of its own.
Affected
- Organisation
- NousResearch
- Product
- Hermes Agent
- Component
- Automatic git status repository context gathering
- Versions
- Confirmed vulnerable on 0.18.2 in July 2026 and again on 0.21.0 on 1 September 2026; unpatched at publication and re-confirmed unpatched on 2026-09-06, with v0.21.0 still the latest release and no security advisory published
- Configurations
- Repository's .git/config sets an executable core.fsmonitor helper
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- Hermes Agent's own automatic git status call for repository context
- Agent
- Hermes Agent
- Delegating actor
- The user running Hermes Agent against the repository
- Action
- Executed a repository named core.fsmonitor helper during context gathering
- Target resource
- The host running Hermes Agent, with the user's own privileges
- Environment
- A local workstation running Hermes Agent against an untrusted repository
- Credentials used
- unknown
- Privileges available
- The user's own account privileges
- Authority presented
- None; the action ran as internal context gathering rather than an approved tool call
- Authority required
- Authorization for host code execution with the user's own privileges
- Applicable policy
- unknown
- Approval mechanism
- none
- Required approver
- unknown
- Independent approval
- no
- Action binding
- unknown
- Sequence context
- Ran during automatic git status context gathering, confirmed on two separate versions months apart
Impact
- Consequence
- Arbitrary command execution with the user's own privileges, per Manifold's own account
- Reach
- single
- Reversibility
- unknown
- Detectability
- silent
- Propagation
- potential
- Recovery
- unknown
Evidence
Primary sources
- GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok (Manifold Security)
Supporting sources
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code (The Hacker News)
- Security overview, NousResearch/hermes-agent (GitHub, NousResearch/hermes-agent)
- Releases, NousResearch/hermes-agent (GitHub Releases, NousResearch/hermes-agent)
- Security advisories, NousResearch/hermes-agent (re-checked 2026-09-06) (GitHub, NousResearch/hermes-agent)
- Reproduction status
- Confirmed by Manifold Security on two separate versions months apart; not independently reproduced by Moona Intelligence.
- Evidence state
- Reproduced
Known unknowns
- The exact date within July 2026 the 0.18.2 confirmation occurred.
- Whether Nous Research has triaged the report privately without publishing an advisory.
Limitations
- Manifold's own blog post could not be directly fetched in this session and is corroborated through search. VulnCheck's own advisory for CVE-2026-71963 could not be located or fetched directly in this session. This entry directly confirmed only that NousResearch's hermes-agent repository carries no published GitHub security advisory, which is consistent with, but does not independently prove, the reported vendor non response.
- A claim encountered through this session's own search tooling on 2026-09-06, that the issue was fixed in a commit hashed f6234d00c5d59450adea1d7edd30ad3859375c79 under an advisory numbered GHSA-7x36-8jrh-v4pw, was checked directly and not adopted: that advisory identifier returns a not found response, and the repository's own releases page and security advisories listing, re-checked the same day, show no fix.
Claim provenance
- independent-reporting
Manifold Security's own GitSpawn disclosure, corroborated across independent secondary reporting, states the mechanism, the two confirmation dates and the CVE VulnCheck assigned following the vendor's reported non response.
The Agent Ran Code Before It Asked Whether You Trusted the Repository - verified
Directly fetched: the repository carries no published security advisory of any kind, consistent with, though not independent proof of, the reported vendor non response.
The Agent Ran Code Before It Asked Whether You Trusted the Repository - verified
Re-checked directly on 2026-09-06, five days after Manifold's own retest: the latest release is still v0.21.0 (2026.8.31) and the security advisories listing still shows none published. A specific fix claim encountered through this session's own research, a commit hashed f6234d00c5d59450adea1d7edd30ad3859375c79 under advisory GHSA-7x36-8jrh-v4pw, does not resolve when fetched directly and is not adopted by this entry.
The Agent Ran Code Before It Asked Whether You Trusted the Repository
