Impact
The vulnerability resides in the CheckShellCommand method of Mercury Agent's Shell Permission Manifest. An attacker able to execute a crafted manipulation locally can cause the function to leak sensitive data that should not be exposed. The flaw stems from improper validation of input permissions, leading to an information disclosure weakness (CWE-200) and a lack of access control (CWE-284).
Affected Systems
Affected systems include cosmicstack‑labs Mercury Agent releases up to version 1.2.0. The critical code is located in mercury‑agent/src/capabilities/permissions.ts. Any installation of these versions that allows local shell execution is vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The exploitation vector is local execution; the public exploit has been published, allowing a local attacker to instantiate the issue. Because no patch has yet been released, the risk remains a potential medium threat for environments where the Mercury Agent runs with elevated privileges.
OpenCVE Enrichment