Impact
This vulnerability arises from an improper privilege management flaw in the checkShellCommand function of the Shell Command Permission component. An attacker can manipulate the input to the function to receive elevated privileges, allowing the execution of arbitrary shell commands with higher authority than originally granted. The weakness is a classic example of CWE‑266, where incorrect privilege assignment can lead to privilege escalation.
Affected Systems
The affected product is CosmicStack Labs Mercury Agent, versions up to 1.2.0. The flaw resides in the permissions.ts source file within the capabilities module.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The exploit is reported as publicly disclosed and can be triggered remotely, although no EPSS data is available and it is not listed in the CISA KEV catalog. The remote attack vector and lack of immediate patch raise the risk of unauthorized privilege escalation, especially in environments where the agent runs with sufficient rights to perform critical operations.
OpenCVE Enrichment