Hermes Agent versions 0.18.2 prior to 0.19.0 contains a critical supply chain vulnerability in its bundled MCP catalog. The flaw arises from referencing a third-party upstream repository via a mutable branch instead of a pinned commit SHA. An attacker who compromises the upstream repository can inject malicious code that propagates automatically to every host installing the affected catalog entry. No further action is required by the operator for exploitation, making the attack vector particularly dangerous. The vulnerability allows remote arbitrary code execution across all affected deployments. A fix has been released in version 0.19.0, with the remediation tracked via a specific commit and pull request on GitHub. The issue was also documented by VulnCheck as a high-severity advisory. Organizations using the affected Hermes Agent versions should update immediately to mitigate risk.