A vulnerability described as critical has been identified in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function
_check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2026-18773. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.