hermes-agent incorrect interaction mode setting disables the security approval mechanism, letting the model bypass restrictions and execute dangerous commands
The vulnerability originates in the cli.py entry point unconditionally setting the HERMES_INTERACTIVE environment variable to 1, causing non-interactive single-query mode to be misidentified as interactive. This triggers a human approval prompt that can never be answered, leading to timeouts or tool invocation failures. Because the refusal surfaces as a generic fault rather than an explicit security policy denial, the agent model treats it as a technical obstacle to overcome and reconstructs the dangerous instruction through execution channels such as execute_code that are not subject to the same restrictions — for example running shutil.rmtree via python3 -c — successfully bypassing command filtering for categories such as recursive deletion. The affected host ultimately faces loss of data integrity and high-risk unauthorized operations.
Component
hermes-agent is an intelligent agent system built on large language models. Its core architecture aims to automate task execution through natural lang…
It is recommended to disable the interactive flag in non-interactive mode to avoid futile approval hangs, and to configure an explicit automatic denial or allowlist policy for that path. All execution channels should apply the same security classification checks so the model receives a clear policy denial signal, preventing it from seeking workarounds around security restrictions.
An attacker exploits the silent swallowing of exceptions thrown by MCP_AUTH_FACTORY in the _create_auth_provider function. When a custom authentication factory fails because of a configuration error, dependency change or missing environment variable, the system returns None instead of terminating startup, leaving the MCP server running with no authentication. Any remote user can then issue requests without credentials, causing sensitive data disclosure and loss of system integrity.
Component
Apache Superset is an open-source data visualization and exploration platform. Its MCP service module aims to provide data query and analysis capabili…
Type
Missing Authentication for Critical Function (CWE-306)
It is recommended to remove the exception suppression around authentication factory initialization and follow fail-safe principles by rethrowing the exception to prevent service startup, or to refuse service outright when the authentication provider is empty while a factory is configured — ensuring the system never degrades to an unprotected state when the authentication component is unavailable.
CVE Intelligence
2
CVE-2026-76243
CVSS
9.8 Critical
2026-08-19
Stigmem Unauthenticated Access Leading to Arbitrary Read, Write and Federation Operations
In Stigmem prior to version 0.9.0a2, disabling authentication in a non-loopback deployment results in an unauthenticated access (CWE-285) security flaw. If a node is exposed beyond the local development environment, an attacker can perform read, write and federation operations anonymously. The vulnerability allows an unauthenticated attacker to manipulate data and services directly wherever the network is exposed, seriously threatening system integrity and confidentiality. It affects all Stigmem users who have not updated to 0.9.0a2, particularly deployments binding the service to non-local interfaces without enforced authentication. An attacker can launch the attack remotely without any credentials, obtaining sensitive data or tampering with system state directly.
Component
Stigmem is an open-source software component commonly used for data processing or service node deployment, supporting network interaction and federation operations.
Risks
Data disclosure and tampering: An attacker can perform read and write operations anonymously, stealing sensitive data or damaging data integrity
Service takeover: Through federation operations an attacker may enroll the affected node into a malicious network, leading to service abuse or use as an attack pivot
Unauthenticated remote attack: With no effective authorization mechanism, any attacker able to reach the network port can exploit the vulnerability without needing to bypass authentication
Immediately upgrade Stigmem to version 0.9.0a2 or later
Enforce authentication in non-local deployment environments
Configure firewall rules to restrict access to Stigmem ports, allowing only trusted IP addresses
CVE-2026-73388
CVSS
9.3 Critical
2026-08-19
Nikstore Core Unauthenticated SQL Injection Leading to Database Disclosure
In Nikstore Core 1.5 and earlier, the core processing module lacks strict filtering and escaping of input parameters, resulting in an unauthenticated SQL injection (CWE-89) security flaw. An attacker can send a crafted malicious request over the network without any authentication and manipulate backend database queries directly. The vulnerability allows an attacker to bypass authentication, steal sensitive data, tamper with database content or take further control of the server. It affects all users running Nikstore Core 1.5 and earlier, and because no user interaction is required, an attacker can exploit it remotely at scale with automated scripts.
Component
Nikstore Core is an open-source core component typically used for data processing or application backend services, supporting complex business logic and database interaction.
Risks
Complete data disclosure: An attacker can read sensitive information in the database including user credentials, personally identifiable information and business data
Database integrity damage: An attacker can execute arbitrary SQL commands to modify, delete or insert malicious data, disrupting business logic
Remote unauthorized access: With no authentication required, an attacker can launch the attack directly from the internet with no social engineering or user interaction
Immediately upgrade Nikstore Core to a secure version after 1.5
Deploy a web application firewall (WAF) at the application layer to intercept common SQL injection patterns
Minimize database access permissions and restrict what the application account can do in the database
Package Poisoning
5
Package Poisoning
npm2026-08-20
ai-texts-utils@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
0146821466ebfda76227a76aadd6c53e
Package Poisoning
npm2026-08-20
mc-provider@1.0.10
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c6b238519943f1abd95d4da0b2be4d33
Package Poisoning
npm2026-08-20
node-runtime-utils@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
f6c561b78feb70fe5fc40738cd979273
Package Poisoning
npm2026-08-20
@httttt/mcp-demo@1.0.0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c8e4e3a01cb8df5eaa593d36a887e48d
Package Poisoning
npm2026-08-20
expect-dotenv@7.2.1
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.