CVE-2026-90812: cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkShellCommand privileges assignment
A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
The issue affects cosmicstack-labs mercury-agent versions up to and including 1.2.0.
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and has low attack complexity, but it requires low-level privileges. No user interaction is required.
Is exploitation publicly available?
Yes. The exploit has been publicly disclosed and may be used.
Is a vendor fix or response identified?
No response from the project is identified in the available data, despite an earlier issue report. No remediation version is provided.