Impact
The vulnerability resides in the PermissionManager.checkShellCommand function within Mercury Agent. The function is intended to block unauthorized users from executing shell commands, but a flaw allows attackers to bypass the check. As a result, an attacker can run arbitrary shell commands with the privileges granted to the agent. This improper authorization issue is categorized as CWE‑266 (Improper Privilege Management) and CWE‑285 (Improper Authorization). The impact is the execution of privileged shell commands that the user should not be able to run, potentially leading to privilege escalation or remote code compromise.
Affected Systems
Mercury Agent from Cosmic Stack Labs, up through version 1.1.13, is affected. The vulnerability is present in the Shell Command Permission Check component, specifically the permissions.ts module. All releases of the agent are listed in the CPE entry, meaning that any version until an official fix exists could be impacted. No additional vendor distribution or packaging information is supplied.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the probability of exploitation cannot be quantified. The description states that attacks can be launched remotely and that a public exploit has been released. The lack of a KEV listing suggests no known large‑scale exploitation yet, but the existence of a public exploit and the vendor’s lack of response increase the risk window. The attack vector is remote, relying on the ability to trigger the vulnerability via the Shell Command Permission Check component without further privileged access.
OpenCVE Enrichment