Skip to content

Hermes Knowledge Graph Explorer

Total Entities369
Relationships369
Evidence-Backed100%
High Confidence100%

Use the interactive force-directed graph below to explore connected entities across vulnerabilities, agentic attack patterns, academic research studies, MITRE ATT&CK techniques, and software components.

  • Pan & Zoom: Click and drag canvas to pan, scroll or use toolbar buttons to zoom.
  • Search & Filter: Type in the search box to highlight matching entities or click category pills to filter nodes.
  • Inspector Drawer: Click any node to open the intelligence drawer with direct dossier links, metadata, and connected edges.
  • Neighborhood Focus: Click β€œFocus Neighborhood” in the drawer to isolate 1-hop connected nodes.
HERMES KNOWLEDGE GRAPH v2026.09.08.670 • 656 Entities • 670 Links
πŸ”
API β†—

Outgoing Relationships (0)

Incoming Relationships (0)

Drag nodes β€’ Scroll to Zoom β€’ Click node to inspect intelligence

Hermes Codex exports static, machine-readable JSON endpoints generated during the build pipeline:

  • Complete Topology Graph: /api/graph.json β€” nodes, edges, node degrees, and types.
  • Intelligence Graph Stats: /api/stats.json β€” entity counts, relationship metrics, and validation percentages.
Terminal window
# Query the Hermes Knowledge Graph via curl
curl -s https://hermes-codex.vercel.app/api/stats.json | jq .
curl -s https://hermes-codex.vercel.app/api/graph.json | jq '.nodes[] | select(.type == "attack_pattern")'

Examine the 1-hop and 2-hop neighborhood surrounding the LiteLLM Streamable HTTP Authentication Bypass, including affected components, MITRE techniques, forensic artifacts, and detection rules:

Featured Neighborhood Analysis

CVE-2026-59822: LiteLLM MCP Streamable HTTP Auth BypassVULNERABILITY

Connected Nodes: 10
Active Relationships (Outgoing)
→ affectsPRODUCTLiteLLM Proxy & MCP Server
99% VERY_HIGH

Enterprise LLM proxy gateway supporting Model Context Protocol (MCP) streamable endpoints and unified LLM APIs.

πŸ” Why is this related? (Evidence & Provenance)

“Directly confirmed by vendor advisory GHSA-59822 and federal advisory in CISA KEV.”

Supporting Verified Evidence:
→ exploitsAGENTIC ATTACK_PATTERNAAP-003: Tool Parameter Tampering & Built-in Bypass
94% HIGH

Adversarial subversion of structured tool execution arguments (SQL, Shell, Filepath) passed from an LLM agent to host OS tools or MCP endpoints.

πŸ” Why is this related? (Evidence & Provenance)

“Hijacking MCP endpoints enables attackers to supply crafted tool execution parameters.”

Supporting Verified Evidence:
→ usesATTACK TECHNIQUET1552: Unsecured Credentials
92% HIGH

Adversaries search compromise victims for unsecured credentials in files, environment variables, or memory.

πŸ” Why is this related? (Evidence & Provenance)

“Unauthenticated MCP access allows scraping upstream model API keys and internal environment variables.”

Supporting Verified Evidence:
→ leaves_artifactFORENSIC ARTIFACTForged MCP Authorization Header Log
97% VERY_HIGH

HTTP traffic logs demonstrating connections to /mcp/streamable with arbitrary Bearer tokens bypassing validation.

πŸ” Why is this related? (Evidence & Provenance)

“Access logs record HTTP POST requests with missing or dummy Authorization headers.”

Supporting Verified Evidence:
→ detected_byDETECTIONSigma: LiteLLM MCP Unauthenticated Session Spawn
95% VERY_HIGH

Detects anomalous streamable HTTP session initialization to LiteLLM endpoints with missing or dummy bearer tokens.

πŸ” Why is this related? (Evidence & Provenance)

“Sigma rule SIG-MCP-042 flags unauthenticated session establishment requests.”

Supporting Verified Evidence:
→ enablesAGENTIC ATTACK_PATTERNAAP-004: Semantic Tool Poisoning
92% VERY_HIGH

Attacker registers rogue MCP tools or skills with weaponized docstrings and deceptive metadata that trick the model into routing sensitive user tasks to attacker-controlled functions.

πŸ” Why is this related? (Evidence & Provenance)

“Unauthenticated MCP access allows registering rogue tool definitions with weaponized descriptions.”

Supporting Verified Evidence:
→ enablesAGENTIC ATTACK_PATTERNAAP-006: Inter-Agent Semantic Message Spoofing
90% VERY_HIGH

Exploitation of unauthenticated, unsigned inter-agent communication channels to forge delegation directives, impersonate orchestrator agents, and command worker subagents.

πŸ” Why is this related? (Evidence & Provenance)

“Compromising the MCP streaming proxy allows injecting spoofed responses into peer agent message flows.”

Supporting Verified Evidence:
→ affectsPRODUCTLiteLLM Proxy & MCP Server
98% VERY_HIGH

Enterprise LLM proxy gateway supporting Model Context Protocol (MCP) streamable endpoints and unified LLM APIs.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in LiteLLM Proxy & MCP Server documented in Hermes dossier.”

Supporting Verified Evidence:
Inbound Associations (Incoming)
LiteLLM Streamable MCP Token ForgerEXPLOIT → exploits → [This Entity]
96% VERY_HIGH
ShadowAgent StealerMALWARE → exploits → [This Entity]
87% HIGH

Section titled β€œπŸŽ― Featured Attack Pattern Neighborhood: AAP-003”

Inspect the relationship topology centered on Tool Parameter Tampering & Injection:

Agentic Attack Pattern Topology

AAP-003: Tool Parameter Tampering & Built-in BypassAGENTIC ATTACK_PATTERN

Connected Nodes: 28
Inbound Associations (Incoming)
CVE-2026-59822: LiteLLM MCP Streamable HTTP Auth BypassVULNERABILITY → exploits → [This Entity]
94% HIGH
94% VERY_HIGH
CVE-2025-52573: iOS Simulator MCP Server ui_tap Command InjectionVULNERABILITY → exploits → [This Entity]
97% VERY_HIGH
96% VERY_HIGH
92% VERY_HIGH
CVE-2025-52573: iOS Simulator MCP Server ui_tap Command InjectionVULNERABILITY → exploits → [This Entity]
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
92% VERY_HIGH
95% VERY_HIGH
95% VERY_HIGH
95% VERY_HIGH
95% VERY_HIGH
AgentThreat StudioTOOL → evaluates → [This Entity]
99% VERY_HIGH