Description
A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Shell Command Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability in cosmicstack-labs mercury-agent originates from an incorrect order of operations in the checkShellCommand function, where input validation occurs before canonicalization. This flaw allows a remote attacker to inject arbitrary shell commands, leading to the execution of unintended system-level commands. The vulnerability is categorized under the Shell Command Execution capability, enabling a full compromise of the host running the agent if exploited. The chain of events delivers immediate code execution without requiring additional privileges beyond the context of the running service.

Affected Systems

The affected product is cosmicstack-labs mercury-agent, specifically versions up to and including 1.1.13. No patch or fix is currently listed for this version range, and any newer releases would need to be verified for a mitigation. The vulnerability impacts the component responsible for permissions checks in the shell command execution flow.

Risk and Exploitability

With a CVSS score of 5.3 the flaw is considered moderate in severity, yet the exploit is publicly available and can be launched remotely. The EPSS score is not reported, and the vulnerability is not currently listed in the CISA KEV catalog, but the lack of a vendor response and public exploitation mean the risk remains significant for any exposed instance. Attackers who can reach the agent over the network can trigger arbitrary commands, potentially escalating privileges or disrupting services. The absence of a formal patch or workaround heightens the urgency of mitigating exposure through updates or network restrictions.

Generated by OpenCVE AI on September 15, 2026 at 07:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade cosmicstack-labs mercury-agent to a version that addresses the checkShellCommand ordering flaw (e.g., 1.1.14 or later if released).
  • If an updated version is unavailable, restrict external network access to the mercury-agent service by implementing firewall rules, IP whitelisting, or VPN boundaries to limit exposed attack surfaces.
  • Disable or remove the Shell Command Execution capability in the agent’s configuration if it is not required for your deployment.

Generated by OpenCVE AI on September 15, 2026 at 07:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title cosmicstack-labs mercury-agent Shell Command Execution permissions.ts checkShellCommand validate before canonicalize
First Time appeared Cosmicstack-labs
Cosmicstack-labs mercury-agent
Weaknesses CWE-179
CWE-180
CPEs cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:*
Vendors & Products Cosmicstack-labs
Cosmicstack-labs mercury-agent
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cosmicstack-labs Mercury-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T19:33:37.520Z

Reserved: 2026-09-13T16:29:51.835Z

Link: CVE-2026-90813

cve-icon Vulnrichment

Updated: 2026-09-14T19:33:33.407Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:17:02.510

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:45:15Z

Weaknesses
  • CWE-179

    Incorrect Behavior Order: Early Validation

  • CWE-180

    Incorrect Behavior Order: Validate Before Canonicalize