A security vulnerability has been identified in the Hermes Agent's MCP Catalog, specifically concerning the lack of a commit SHA pin for installation. This oversight allows for remote code execution (RCE) because the catalog, which acts as an install pin, uses a mutable branch reference instead of a fixed integrity check. AI
IMPACT Potential security risk for users of the Hermes Agent and its MCP Catalog.
RANK_REASON Identifies a specific security vulnerability in a software component.
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →