CVE-2026-90813 | cosmicstack-labs mercury-agent up to 1.1.13 Shell Command Execution permissions.ts checkShellCommand validate before canonicalize (Issue 95)
A vulnerability, which was classified as problematic, was found in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize.
This vulnerability is cataloged as CVE-2026-90813. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More