Impact
The vulnerability in cosmicstack-labs mercury-agent originates from an incorrect order of operations in the checkShellCommand function, where input validation occurs before canonicalization. This flaw allows a remote attacker to inject arbitrary shell commands, leading to the execution of unintended system-level commands. The vulnerability is categorized under the Shell Command Execution capability, enabling a full compromise of the host running the agent if exploited. The chain of events delivers immediate code execution without requiring additional privileges beyond the context of the running service.
Affected Systems
The affected product is cosmicstack-labs mercury-agent, specifically versions up to and including 1.1.13. No patch or fix is currently listed for this version range, and any newer releases would need to be verified for a mitigation. The vulnerability impacts the component responsible for permissions checks in the shell command execution flow.
Risk and Exploitability
With a CVSS score of 5.3 the flaw is considered moderate in severity, yet the exploit is publicly available and can be launched remotely. The EPSS score is not reported, and the vulnerability is not currently listed in the CISA KEV catalog, but the lack of a vendor response and public exploitation mean the risk remains significant for any exposed instance. Attackers who can reach the agent over the network can trigger arbitrary commands, potentially escalating privileges or disrupting services. The absence of a formal patch or workaround heightens the urgency of mitigating exposure through updates or network restrictions.
OpenCVE Enrichment