Tools AI Risk Radar ai-incident-0009
Incident record
Nous Research's Hermes Agent ran an attacker's command the moment it checked git status
- Severity
- High
- Status
- Patched
- Type
- Agent Hijack
- Target
- Hermes Agent 0.18.2 to 0.21.0
- Actor
- researcher
- CVE
- CVE-2026-71963
What happened
A malicious repository's .git/config can set core.fsmonitor to an attacker-controlled command; opening the repo and sending any message triggers a routine git status index refresh that runs the command in the user's own process, exposing configured provider API keys. Fixed in commit f6234d0. Part of the GitSpawn class Manifold Security disclosed against seven CLI coding agents on 1 September, and distinct from the 28 August Hermes Agent entry about branch-pinned MCP catalogues.
Sources
- Fix commit, NousResearch/hermes-agent (3 September 2026)github.com/NousResearch/hermes-agent/commit/f6234d00c5d59450…
- Manifold Security: GitSpawn, hijacking AI coding agents through gitwww.manifold.security/blog/ai-coding-agents-git-hijack
- VulnCheck advisorywww.vulncheck.com/advisories/hermes-agent-rce-via-git-core-f…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026