All vulnerabilities

CVE-2026-NONE · GHSA-9mpj-6v9h-42pj

hermes-action-bridge: hermes_approve accepts its own prior tool call as human approval, letting unreviewed side effects execute

highCWE-862
Vendor
TheBlueHouse75
Package
hermes-action-bridge npm
Affected
<= 0.6.2
Fixed in
0.6.3
Disclosed
2026-08
Credit
Avishai Gonen
missing-confirmationmcpprompt-injection