CVE-2026-18997: cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18997?
The severity of CVE-2026-18997 is medium with a CVSS score of 6.3.
How do I fix CVE-2026-18997?
To fix CVE-2026-18997, update the cosmicstack-labs mercury-agent to version 1.1.13 or later.
What components are affected by CVE-2026-18997?
CVE-2026-18997 affects the bg Command Handler in the Agent.handleBgCommand function of the cosmicstack-labs mercury-agent.
What type of vulnerability is CVE-2026-18997?
CVE-2026-18997 is an authorization vulnerability that can lead to incorrect authorization handling.
Can CVE-2026-18997 be exploited remotely?
Yes, CVE-2026-18997 can be exploited remotely due to its nature in the Agent.handleBgCommand function.