SNACK: 3-line summary
- Hermes Agent v0.21.6 fixes security issues in dashboard login, automatic Git operations and the email gateway.
- The fixes address session takeover risk and repository-defined programs that could run before the first prompt.
- Follow the update path for your installation; Desktop, Termux and Microsoft Store builds are unchanged in this patch.
Nous Research released Hermes Agent v0.21.6 on October 8, 2026, with security fixes for dashboard login, automatic Git operations and email sender checks. Hermes is an autonomous AI agent with terminal tools and messaging integrations.

Snackgirls react
AIKO: I’m curious how Hermes keeps a sender’s display name separate from permission to contact the agent. A label is not an access badge.
Red: I want to hand Hermes a new project and start making things. First, though, I’d check where the repo came from.
Login redirects, rate limits and logs
The official release notes describe a native sign-in flaw that could send login codes to a non-loopback redirect destination, allowing session takeover. The patch fixes that redirect issue.
Spoofed X-Forwarded-For headers could also bypass password-login rate limits and the per-IP cap on native sign-in. Other dashboard fixes address unauthenticated login requests that could write unbounded values to the authentication audit log, and missing request-body size limits on public /auth/ routes.
Git filters and email display names
An untrusted repository’s own configuration could define clean, smudge or process filter programs that automatic Git calls would execute during operations such as workspace snapshots or subagent worktree creation—even before the first prompt. The release hardens those calls. An untrusted repository should not be treated as passive text just because the agent has not received a prompt.
The email gateway fix concerns sender identification: a crafted From display name could make an attacker’s message pass the sender allowlist. The display name is the label shown to the reader, not the actual sender address the allowlist is meant to check.
Choose the update route for your installation
For Git-installed CLI users, the official update route is hermes update or rerunning the installer. Docker and Hermes Cloud have a separate route, listed in the release notes as nousresearch/hermes-agent:stable or :latest; the CLI command should not be treated as a container-image update.
The Desktop app, Termux packages and Microsoft Store build remain unchanged in this patch. They will move with the next bundled release, so Desktop users should not assume their app has already received v0.21.6.
Sources and date: 2026-10-11

Comments
0No login needed. Edit or delete your comment from the same browser.
All comments 0
한국어 · English · 日本語No comments yet. Start the conversation.