CVE-2026-18998: cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegatetask Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18998?
CVE-2026-18998 has a severity rating of medium, with a score of 6.3.
What impact does CVE-2026-18998 have?
CVE-2026-18998 can lead to improper authorization when exploiting the vulnerable function SubAgent.run.
How can I remediate CVE-2026-18998?
To fix CVE-2026-18998, update the cosmicstack-labs mercury-agent to version 1.1.13 or later.
Is CVE-2026-18998 exploitable remotely?
Yes, CVE-2026-18998 can be exploited remotely.
What software is affected by CVE-2026-18998?
CVE-2026-18998 affects cosmicstack-labs mercury-agent versions up to 1.1.12.