YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0009

Incident record

Nous Research's Hermes Agent ran an attacker's command the moment it checked git status

Severity
High
Status
Patched
Type
Agent Hijack
Target
Hermes Agent 0.18.2 to 0.21.0
Actor
researcher
CVE
CVE-2026-71963

What happened

A malicious repository's .git/config can set core.fsmonitor to an attacker-controlled command; opening the repo and sending any message triggers a routine git status index refresh that runs the command in the user's own process, exposing configured provider API keys. Fixed in commit f6234d0. Part of the GitSpawn class Manifold Security disclosed against seven CLI coding agents on 1 September, and distinct from the 28 August Hermes Agent entry about branch-pinned MCP catalogues.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026