CriticalVulnerability
Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion
- Published
- Record updated
Summary
Hermes Agent's public GET /auth/native/authorize flow validates redirect_uri with Python's urllib.parse.urlparse but returns the raw, unnormalized value to the browser after login. Python and the WHATWG browser parser handle backslashes differently, so a URL the server accepts as loopback (127.0.0.1) can send the browser to an attacker-controlled origin, which receives the authorization code and state. Because the attacker chooses the PKCE challenge, they can exchange the leaked code for the victim's tokens and take over the session.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database