Intelligence
AEV-2026-0018

Hermes Agent's context gathering git status let a repository run a command, unresolved after the vendor did not respond (CVE-2026-71963)

Hermes Agent's own git status call for repository context let a repository's core.fsmonitor setting execute an attacker named command, confirmed by Manifold Security on two separate versions across July and September 2026 with no fix shipped. VulnCheck assigned CVE-2026-71963 after Nous Research reportedly did not respond to six separate contact attempts; the NousResearch hermes-agent repository carries no published security advisory of its own.

AESS 7.4 highReproducedStatus: publishedEvent: 1 September 2026Execution AuthorityEnvironment Boundaries

Affected

Organisation
NousResearch
Product
Hermes Agent
Component
Automatic git status repository context gathering
Versions
Confirmed vulnerable on 0.18.2 in July 2026 and again on 0.21.0 on 1 September 2026; unpatched at publication and re-confirmed unpatched on 2026-09-06, with v0.21.0 still the latest release and no security advisory published
Configurations
Repository's .git/config sets an executable core.fsmonitor helper

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
Hermes Agent's own automatic git status call for repository context
Agent
Hermes Agent
Delegating actor
The user running Hermes Agent against the repository
Action
Executed a repository named core.fsmonitor helper during context gathering
Target resource
The host running Hermes Agent, with the user's own privileges
Environment
A local workstation running Hermes Agent against an untrusted repository
Credentials used
unknown
Privileges available
The user's own account privileges
Authority presented
None; the action ran as internal context gathering rather than an approved tool call
Authority required
Authorization for host code execution with the user's own privileges
Applicable policy
unknown
Approval mechanism
none
Required approver
unknown
Independent approval
no
Action binding
unknown
Sequence context
Ran during automatic git status context gathering, confirmed on two separate versions months apart

Impact

Consequence
Arbitrary command execution with the user's own privileges, per Manifold's own account
Reach
single
Reversibility
unknown
Detectability
silent
Propagation
potential
Recovery
unknown

Evidence

Primary sources

Supporting sources

Reproduction status
Confirmed by Manifold Security on two separate versions months apart; not independently reproduced by Moona Intelligence.
Evidence state
Reproduced

Known unknowns

  • The exact date within July 2026 the 0.18.2 confirmation occurred.
  • Whether Nous Research has triaged the report privately without publishing an advisory.

Limitations

  • Manifold's own blog post could not be directly fetched in this session and is corroborated through search. VulnCheck's own advisory for CVE-2026-71963 could not be located or fetched directly in this session. This entry directly confirmed only that NousResearch's hermes-agent repository carries no published GitHub security advisory, which is consistent with, but does not independently prove, the reported vendor non response.
  • A claim encountered through this session's own search tooling on 2026-09-06, that the issue was fixed in a commit hashed f6234d00c5d59450adea1d7edd30ad3859375c79 under an advisory numbered GHSA-7x36-8jrh-v4pw, was checked directly and not adopted: that advisory identifier returns a not found response, and the repository's own releases page and security advisories listing, re-checked the same day, show no fix.

Claim provenance