Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion

Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion Note: Another researcher identified the same vulnerability during the disclosure process with the Nous Researcher team. In Hermes Agent, the public GET /auth/native/authorize flow validates the redirect_uri with Python's…

devsciencesecurity

Sources