Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkShellCommand privileges assignment | |
| First Time appeared |
Cosmicstack-labs
Cosmicstack-labs mercury-agent |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cosmicstack-labs
Cosmicstack-labs mercury-agent |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T19:00:09.686Z
Reserved: 2026-09-13T16:29:48.552Z
Link: CVE-2026-90812
No data.
Status : Deferred
Published: 2026-09-14T19:18:12.257
Modified: 2026-09-14T20:56:48.220
Link: CVE-2026-90812
No data.
OpenCVE Enrichment
No data.