Evidence record / hermes-agent
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.
2026-09-21-hermes-agent-ghsa-7x36-8jrh-v4pw-a-copied-repo-s-git-config-could-run-code-on-the-host-before-any-promp
GHSA-7x36-8jrh-v4pw: a copied repo’s .git/config could run code on the host before any prompt (fixed v2026.9.7). GHSA-7x36-8jrh-v4pw: a copied repo’s .git/config could run code on the host before any prompt (fixed v2026.9.7)
Channel: tagged-release. Half: defect. Date: commit 2026-09-02; tagged 2026-09-07.
Operator consequence: Every tag through v2026.8.31 is exposed. Upgrade to v2026.9.7 or later before opening Hermes in any directory you did not create or clone yourself. Project-skill trust (hermes skills trust) never gated this path; the exposure was pre-trust.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-hermes-agent-ghsa-7x36-8jrh-v4pw-a-copied-repo-s-git-config-could-run-code-on-the-host-before-any-promp
Accepted signals
Profile citations
- Hermes Agent / claim / gitspawn-fixed-v2026-9-7
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact