Impact
The vulnerability is a server‑side request forgery (CWE‑918) in the githubRequest function of the GitHub API handler within Mercury Agent. By manipulating the path argument, an attacker can cause the application to issue arbitrary HTTP requests to external servers. Remote exploitation is possible, allowing attackers to access internal resources, exfiltrate data or perform denial‑of‑service actions. The flaw is available in all releases up to and including 1.1.13 and has been publicly demonstrated.
Affected Systems
Mercury Agent from cosmicstack‑labs, versions up to 1.1.13. The affected component is the src/utils/github.ts file in the GitHub API handler of the agent.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an interface that leads to githubRequest, such as an exposed API endpoint or webhook handler, and it is inferred that a crafted payload could trigger outbound requests to arbitrary URLs.
OpenCVE Enrichment