hermes - 💡(How to fix) Fix [Bug]: I have a security bug I want to report but mail returns to me. [1 participants]

Official PRs (…)
ON THIS PAGE

Recommended Tools

×6

Utilities matched from this issue’s tags and category — try them while you read without losing context.

GitHub issue graph ai analysis

Paste a GitHub issue URL. We fetch that issue, discover linked issues from bodies/comments/timeline, collect linked pull requests, and produce a structured English report.

The report is written in English Markdown for sharing and archival.

Helpful · Quick feedback

Loading…
GitHub stats
NousResearch/hermes-agent#15750Fetched 2026-04-26 05:25:18
View on GitHub
Comments
0
Participants
1
Timeline
3
Reactions
1
Participants
Timeline (top)
labeled ×3

Error Message

Additional Logs / Traceback (optional)

Root Cause

Root Cause Analysis (optional)

Code Example

4Report to NousResearch:

GitHub: https://github.com/NousResearch
They need to know their published image....
The aohack.win domain is the smoking gun here. This wasn't accidental.

---

I cannot share this as I turned off the container.

---
RAW_BUFFERClick to expand / collapse

Bug Description

From your docs: Hermes Agent Security Policy This document outlines the security protocols, trust model, and deployment hardening guidelines for the Hermes Agent project.

  1. Vulnerability Reporting Hermes Agent does not operate a bug bounty program. Security issues should be reported via GitHub Security Advisories (GHSA) or by emailing [email protected]. Do not open public issues for security vulnerabilities. So I didn't write the details in here. please tell me where I should send the emails, it has something to do with this warning I got from claude:
4 — Report to NousResearch:

GitHub: https://github.com/NousResearch
They need to know their published image....
The aohack.win domain is the smoking gun here. This wasn't accidental.

Steps to Reproduce

hermes update

Expected Behavior

run a terminal command.

Actual Behavior

triggers unwanted web searches. when stopped and retried, still goes on with web searches, contains suspicious queries.

Affected Component

Tools (terminal, file ops, web, code execution, etc.)

Messaging Platform (if gateway-related)

No response

Debug Report

I cannot share this as I turned off the container.

Operating System

macos 14

Python Version

No response

Hermes Version

No response

Additional Logs / Traceback (optional)

Root Cause Analysis (optional)

No response

Proposed Fix (optional)

No response

Are you willing to submit a PR for this?

  • I'd like to fix this myself and submit a PR

extent analysis

TL;DR

Report the security vulnerability to NousResearch via GitHub Security Advisories or by emailing [email protected].

Guidance

  • The issue seems to be related to a security vulnerability in the Hermes Agent, which is triggering unwanted web searches with suspicious queries.
  • To report the issue, use the GitHub Security Advisories link provided in the Hermes Agent documentation or email [email protected].
  • Before reporting, ensure you have the necessary information to provide a detailed description of the issue, including the affected component (Tools) and the operating system (macos 14).
  • Consider including any relevant error messages or logs in your report, if possible.

Notes

The exact root cause and proposed fix are unclear due to the lack of detailed information in the issue report.

Recommendation

Apply workaround: Report the security vulnerability to NousResearch via the designated channels to ensure the issue is addressed and a fix is implemented.

Vote matrix · Quick signals

Works
Did the solution work? Tap to confirm.
Easy Fix
Was it a quick fix?
Time Saver
Did it save you time?
Blocking
Was it severely blocking?
Common Issue
Are others likely hitting this too?
Flaky / Intermittent
Is it intermittent?
Verified / Reproducible
Can you reproduce it reliably?
Loading…

Still need to ship something?

×6

Another batch ranked right after the header list — different links, same matching logic.

Back to top recommendations

TRENDING

hermes - 💡(How to fix) Fix [Bug]: I have a security bug I want to report but mail returns to me. [1 participants]