CVE-2026-85106 | NousResearch hermes-agent 0.18.0 Link Title Fetch index.tsx fetchLinkTitle url server-side request forgery
A vulnerability described as critical has been identified in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-85106. The attack can be launched remotely. No exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More