Tools AI Risk Radar ai-incident-0019
Incident record
Hermes Agent shipped an MCP catalogue pinned to a branch instead of a commit
- Severity
- Critical
- Status
- Patched
- Type
- Poisoning
- Target
- Hermes Agent 0.18.2 up to 0.19.0
- Actor
- researcher
- CVE
- CVE-2026-82021
What happened
Hermes Agent referenced a third-party upstream repository in its bundled MCP catalogue by mutable branch pointer rather than a pinned commit. Anyone who compromised that upstream could push code to every host that had installed the catalogue entry, with no action needed from the operator.
Classified CWE-494, download of code without integrity check. CVSS 3.1 scores it 8.3 high and CVSS 4.0 scores it 9.0 critical. A branch reference is a promise that whoever controls the branch controls your machine later, which is the same supply-chain shape as the npm worm already on this board, arriving through an agent tool catalogue instead.
Sources
- VulnCheck advisorywww.vulncheck.com/advisories/hermes-agent-mcp-catalog-supply…
- NVD record, CVE-2026-82021nvd.nist.gov/vuln/detail/CVE-2026-82021
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026