MEDIUM

CVE-2026-53870

2026-06-17 CVSS v3.1
CVSS
5.5

Description

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history, tool payloads, prompts, and per-route HMAC secrets.

Weakness (CWE)

CWE-276 Incorrect Default Permissions

EPSS Score

0.11%
Probability of exploitation in next 30 days
1.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE