Skip to content
CriticalVulnerability

Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion

Published
Record updated
View JSON

Summary

Hermes Agent's public GET /auth/native/authorize flow validates redirect_uri with Python's urllib.parse.urlparse but returns the raw, unnormalized value to the browser after login. Python and the WHATWG browser parser handle backslashes differently, so a URL the server accepts as loopback (127.0.0.1) can send the browser to an attacker-controlled origin, which receives the authorization code and state. Because the attacker chooses the PKCE challenge, they can exchange the leaked code for the victim's tokens and take over the session.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.