{"data":{"id":"b723935e-3173-4bfd-9aa8-e327a58d572b","title":"Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion","summary":"Hermes Agent's public GET /auth/native/authorize flow validates redirect_uri with Python's urllib.parse.urlparse but returns the raw, unnormalized value to the browser after login. Python and the WHATWG browser parser handle backslashes differently, so a URL the server accepts as loopback (127.0.0.1) can send the browser to an attacker-controlled origin, which receives the authorization code and state. Because the attacker chooses the PKCE challenge, they can exchange the leaked code for the victim's tokens and take over the session.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://www.tenable.com/security/research/tra-2026-65","publishedAt":"2026-10-09T15:15:46.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["jailbreak","other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Hermes Agent","Nous Researcher team"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-09T15:15:46.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}