---
id: CVE-2026-90810
title: >-
  A security flaw has been discovered in cosmicstack-labs mercury-agent up to
  1.1.13
summary: >-
  A security flaw has been discovered in cosmicstack-labs mercury-agent up to
  1.1.13. The impacted element is the function
  PermissionManager.checkShellCommand of the file
  mercury-agent/src/capabilities/permissions.ts of the component Shell…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-285
vendor: cosmicstack-labs
product: mercury-agent
affected:
  - mercury-agent 1.1.0
  - mercury-agent 1.1.1
  - mercury-agent 1.1.2
  - mercury-agent 1.1.3
  - mercury-agent 1.1.4
  - mercury-agent 1.1.5
  - mercury-agent 1.1.6
  - mercury-agent 1.1.7
  - mercury-agent 1.1.8
  - mercury-agent 1.1.9
  - mercury-agent 1.1.10
  - mercury-agent 1.1.11
  - mercury-agent 1.1.12
  - mercury-agent 1.1.13
published: '2026-09-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:17:29.697'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90810'
references:
  - url: 'https://github.com/cosmicstack-labs/mercury-agent/'
    label: cna@vuldb.com
  - url: 'https://github.com/cosmicstack-labs/mercury-agent/issues/101'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90810'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/922876'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403312'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403312/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/922876'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T14:54:18.887653Z'
epss: 0.00366
epssPercentile: 0.27664
ingestedAt: '2026-09-14T19:13:23.471Z'
---

## Overview

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
