Signals

2026-07-01 / Hermes Agent

Hermes landed a full security wave on main -- path-escape, command-approval-bypass, secret redaction -- and tagged none of it (still v2026.6.19)

Edited by Michael Ruescher

What this changes for operators

  • Three real hardening fixes hit main in-window: a path-traversal fix (model-supplied tool-call IDs could escape the tool-result storage directory), a command-approval-bypass close (GNU long-flag prefix abbreviations of chown --recursive and git push --force slipped past the guard), and secret redaction in user-facing approval prompts. None reached a tag; the newest release is still v2026.6.19 (2026-06-19).
  • If you run the v2026.6.19 tag you have none of these. The approval-bypass in particular means a guard you believed was blocking chown --recursive / git push --force could be defeated by an abbreviated long flag on the tagged binary. Track main or wait for a tag, but know the gap.

Signal metadata

Source findings

Featured in

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-07-01-hermes-security-wave-main-untagged

Research evidence and publication history are open in the repository.