CVE-2026-18774 | NousResearch hermes-agent up to 0.16.0 xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgery
A vulnerability classified as critical has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery.
This vulnerability appears as CVE-2026-18774. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More