Shell Command Execution Vulnerability in Cosmicstack Labs Mercury Agent
CVE-2026-90813
Key Information:
- Vendor
Cosmicstack-labs
- Status
- Vendor
- CVE Published:
- 14 September 2026
Badges
What is CVE-2026-90813?
A vulnerability in the Cosmicstack Labs Mercury Agent allows for improper handling of shell commands due to an incorrect order of validation and canonicalization. The issue is present in the function checkShellCommand within the src/capabilities/permissions.ts file. This flaw can be exploited remotely, potentially allowing attackers to manipulate the execution of shell commands. Despite an early report to the developers, they have not responded to this critical issue, leaving users exposed.
Affected Version(s)
mercury-agent 1.1.0
mercury-agent 1.1.1
mercury-agent 1.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
