CVE-2026-90810 | cosmicstack-labs mercury-agent up to 1.1.13 Shell Command Permission Check permissions.ts PermissionManager.checkShellCommand improper authorization (Issue 101)

SecurityVulns

A vulnerability classified as critical has been found in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization.

This vulnerability is identified as CVE-2026-90810. The attack can be initiated remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More