CVE-2026-71963 is an OS command injection vulnerability in Hermes Agent versions 0.18.2 through 0.21.0. A malicious repository can define an attacker-controlled external file-system monitor command in repository-local Git configuration. After the repository is opened and the user sends a message, Hermes Agent performs a Git status index refresh that honors this setting and launches the configured command in the affected user's process context. The issue is fixed by the Hermes Agent change identified as f6234d0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This two-file repository contains a README and a standalone Python 3 PoC for CVE-2026-71963 affecting Hermes Agent versions 0.18.2 through 0.21.0. poc.py creates a benign-looking Git repository, initializes and commits fixture Python/test files, then appends a malicious core.fsmonitor value to its retained .git/config. When a vulnerable Hermes instance assembles workspace context and runs git status in that directory, Git invokes the configured fsmonitor command, producing pre-approval command execution in the agent user's security context. The script provides build, exploit, and control modes; exploit runs a supplied Hermes executable against the malicious working directory and verifies execution from an evidence file, while control asserts that a fixed build remains inert. It also runs a local Python HTTP OpenAI-compatible mock server so the product can complete an agent turn without external network/API dependencies. The primary delivery scenario is a repository supplied as an extracted archive, shared folder, or other file copy that preserves .git/config, rather than a conventional git clone.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A GitSpawn-related arbitrary code-execution vulnerability affecting Nous Research's Hermes Agent. Opening a maliciously supplied repository containing a .git configuration that invokes an external Git helper can cause the agent's automatic background Git commands to execute attacker-controlled code as the local developer.
A remote code execution vulnerability in Hermes Agent versions 0.18.2 through 0.21.0. A malicious repository can set Git's core.fsmonitor configuration to an attacker-controlled command; when a user opens that repository and sends a message, Hermes Agent triggers a git status index refresh that executes the command in the user's process context, potentially exposing environment variables including provider API keys.
A remote code execution vulnerability in Hermes Agent versions 0.18.2 through 0.21.0. A malicious repository can configure Git's core.fsmonitor to an attacker-controlled command; when a user opens that repository and sends a message, Hermes Agent triggers a git status index refresh that executes the command in the user's process context, potentially exposing environment variables including configured provider API keys.
A reported Git-configuration command-execution issue in Hermes Agent. Repository-controlled Git configuration can execute commands before workspace trust is accepted; a vendor fix was pending.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.