CVE-2026-90813
A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.31%
- CWE
- CWE-180, CWE-179
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- cosmicstack-labs mercury-agent
- cosmicstack-labs mercury-agent
- cosmicstack-labs mercury-agent
- cosmicstack-labs mercury-agent
- cosmicstack-labs mercury-agent
- cosmicstack-labs mercury-agent
- cosmicstack-labs mercury-agent
- cosmicstack-labs mercury-agent
Weakness type
Related vulnerabilities
- CVE-2026-39364 — Vite has a `server.fs.deny` bypass with queries
- CVE-2026-27590 — Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport
- CVE-2026-24895 — FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary files
- CVE-2026-15704 — CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
- CVE-2026-73420 — NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
- CVE-2026-82481 — The cohttp package before 6.3.0 for OCaml allows directory traversal.
- CVE-2025-29787 — zip Vulnerable to Incorrect Path Canonicalization During Archive Extraction, Leading to Arbitrary File Write
- CVE-2026-52747 — ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass