Impact
The vulnerability lies in the Agent.handleBgCommand function of the mercury-agent background command handler. Manipulating input sent to this function can cause it to accept commands without performing the required authorization checks, resulting in an authorization bypass. This flaw allows remote actors to trigger privileged operations that should otherwise be restricted.
Affected Systems
Affected versions of the cosmicstack-labs mercury-agent include all releases up to 1.1.12. The issue is located in src/core/agent.ts and no later versions have been confirmed to be unaffected. The project has not released a patched build as of the last update.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS information is not available, and the vulnerability has not been listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending crafted background command payloads without needing elevated privileges. An active public exploit exists, and the vendor has not yet responded, increasing the likelihood of real-world exploitation.
OpenCVE Enrichment