No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | cosmicstack-labs mercury-agent Shell Command Execution permissions.ts checkShellCommand validate before canonicalize | |
| First Time appeared |
Cosmicstack-labs
Cosmicstack-labs mercury-agent |
|
| Weaknesses | CWE-179 CWE-180 |
|
| CPEs | cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cosmicstack-labs
Cosmicstack-labs mercury-agent |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T19:33:37.520Z
Reserved: 2026-09-13T16:29:51.835Z
Link: CVE-2026-90813
Updated: 2026-09-14T19:33:33.407Z
Status : Deferred
Published: 2026-09-14T20:17:02.510
Modified: 2026-09-14T20:56:48.220
Link: CVE-2026-90813
No data.
OpenCVE Enrichment
No data.