A vulnerability has been found in NousResearch hermes-agent up to 0.16.0 and classified as critical. This impacts the function
get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment.
This vulnerability appears as CVE-2026-18976. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report.