CVE-2026-71963-PoC
Author
Boreas37
Published
2026-09-27
Stars
0
Forks
0
Repository
Description
CVE-2026-71963 - Hermes Agent 0.18.2-0.21.0 RCE via a repository-delivered .git/config (core.fsmonitor). Stdlib-only Python, verified on real 0.21.0 with a clean negative control on the fixed build.
CVE-CVE-2026-71963 Details
Severity
HIGH
CVSS Score
8.8
CWE
CWE-78
Description
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment inclu...
Related PoCs for CVE-2026-71963
No other PoCs found for this CVE.