Description
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Agent.handleBgCommand function of the mercury-agent background command handler. Manipulating input sent to this function can cause it to accept commands without performing the required authorization checks, resulting in an authorization bypass. This flaw allows remote actors to trigger privileged operations that should otherwise be restricted.

Affected Systems

Affected versions of the cosmicstack-labs mercury-agent include all releases up to 1.1.12. The issue is located in src/core/agent.ts and no later versions have been confirmed to be unaffected. The project has not released a patched build as of the last update.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS information is not available, and the vulnerability has not been listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending crafted background command payloads without needing elevated privileges. An active public exploit exists, and the vendor has not yet responded, increasing the likelihood of real-world exploitation.

Generated by OpenCVE AI on August 6, 2026 at 06:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest mercury‑agent release that contains the fix once it becomes available.
  • Disable or restrict the background command interface for non‑privileged users or add custom authorization checks to ensure only trusted callers can execute commands.
  • Monitor system logs for anomalous background command activity and immediately block offending IPs or user agents.

Generated by OpenCVE AI on August 6, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Title cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
First Time appeared Cosmicstack-labs
Cosmicstack-labs mercury-agent
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:*
Vendors & Products Cosmicstack-labs
Cosmicstack-labs mercury-agent
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Cosmicstack-labs Mercury-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T04:30:10.579Z

Reserved: 2026-08-05T19:41:35.352Z

Link: CVE-2026-18997

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T06:30:03Z

Weaknesses