CVE-2026-53870

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history, tool payloads, prompts, and per-route HMAC secrets.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-17 19:18

Updated : 2026-06-17 20:21


NVD link : CVE-2026-53870

Mitre link : CVE-2026-53870

CVE.ORG link : CVE-2026-53870


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions