Security Advisory

CVE-2026-7396

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-29 17:30:15
Last updated 2026-04-29 19:28:34
Assigner VulDB
CVSS score 6.9
State PUBLISHED

Description

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.