CVE-2026-18997 | cosmicstack-labs mercury-agent up to 1.1.12 bg Command src/core/agent.ts Agent.handleBgCommand authorization (Issue 73)

SecurityVulns

A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. It has been rated as critical. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization.

This vulnerability is cataloged as CVE-2026-18997. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More