Description
A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized execution of privileged shell commands
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the PermissionManager.checkShellCommand function within Mercury Agent. The function is intended to block unauthorized users from executing shell commands, but a flaw allows attackers to bypass the check. As a result, an attacker can run arbitrary shell commands with the privileges granted to the agent. This improper authorization issue is categorized as CWE‑266 (Improper Privilege Management) and CWE‑285 (Improper Authorization). The impact is the execution of privileged shell commands that the user should not be able to run, potentially leading to privilege escalation or remote code compromise.

Affected Systems

Mercury Agent from Cosmic Stack Labs, up through version 1.1.13, is affected. The vulnerability is present in the Shell Command Permission Check component, specifically the permissions.ts module. All releases of the agent are listed in the CPE entry, meaning that any version until an official fix exists could be impacted. No additional vendor distribution or packaging information is supplied.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the probability of exploitation cannot be quantified. The description states that attacks can be launched remotely and that a public exploit has been released. The lack of a KEV listing suggests no known large‑scale exploitation yet, but the existence of a public exploit and the vendor’s lack of response increase the risk window. The attack vector is remote, relying on the ability to trigger the vulnerability via the Shell Command Permission Check component without further privileged access.

Generated by OpenCVE AI on September 15, 2026 at 13:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Review the Mercury Agent configuration to ensure that only trusted users are permitted to invoke shell commands; consider disabling the feature if it is not required.
  • Service hardening: restrict network access to the agent and monitor for unusual shell command activity using logs or intrusion detection systems.
  • Apply custom code changes to enforce stricter permission checks in PermissionManager.checkShellCommand or replace the vulnerable logic until an official fix is released.
  • Maintain system backups and monitor for indicators of compromise that could suggest an attacker has already executed unauthorized commands.
  • Await the vendor’s response and update to a patched or newer version of Mercury Agent as soon as it becomes available.

Generated by OpenCVE AI on September 15, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title cosmicstack-labs mercury-agent Shell Command Permission Check permissions.ts PermissionManager.checkShellCommand improper authorization
First Time appeared Cosmicstack-labs
Cosmicstack-labs mercury-agent
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:*
Vendors & Products Cosmicstack-labs
Cosmicstack-labs mercury-agent
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Cosmicstack-labs Mercury-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:54:24.698Z

Reserved: 2026-09-13T16:29:41.352Z

Link: CVE-2026-90810

cve-icon Vulnrichment

Updated: 2026-09-15T14:54:02.841Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T19:18:11.480

Modified: 2026-09-15T15:17:29.697

Link: CVE-2026-90810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:15:18Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization