Description
A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply patch
AI Analysis

Impact

This vulnerability arises from an improper privilege management flaw in the checkShellCommand function of the Shell Command Permission component. An attacker can manipulate the input to the function to receive elevated privileges, allowing the execution of arbitrary shell commands with higher authority than originally granted. The weakness is a classic example of CWE‑266, where incorrect privilege assignment can lead to privilege escalation.

Affected Systems

The affected product is CosmicStack Labs Mercury Agent, versions up to 1.2.0. The flaw resides in the permissions.ts source file within the capabilities module.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The exploit is reported as publicly disclosed and can be triggered remotely, although no EPSS data is available and it is not listed in the CISA KEV catalog. The remote attack vector and lack of immediate patch raise the risk of unauthorized privilege escalation, especially in environments where the agent runs with sufficient rights to perform critical operations.

Generated by OpenCVE AI on September 15, 2026 at 07:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and apply any official patches or newer releases that address the privilege‑assignment bug.
  • If no patch is available, disable the Shell Command Permission capability or restrict the users who can invoke shell commands to the minimum required set.
  • Monitor agent logs for unusual shell command activity and enforce strict access controls on the host system to prevent misuse.

Generated by OpenCVE AI on September 15, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkShellCommand privileges assignment
First Time appeared Cosmicstack-labs
Cosmicstack-labs mercury-agent
Weaknesses CWE-266
CPEs cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:*
Vendors & Products Cosmicstack-labs
Cosmicstack-labs mercury-agent
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Cosmicstack-labs Mercury-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T16:08:58.364Z

Reserved: 2026-09-13T16:29:48.552Z

Link: CVE-2026-90812

cve-icon Vulnrichment

Updated: 2026-09-16T16:08:52.374Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T19:18:12.257

Modified: 2026-09-16T17:18:17.640

Link: CVE-2026-90812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:45:15Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment