CVE-2026-18998

Source
https://cve.org/CVERecord?id=CVE-2026-18998
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18998.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18998
Published
2026-08-06T04:45:09.185Z
Modified
2026-08-07T11:31:13.527046738Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization
Details

A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.1.1"
                },
                {
                    "last_affected": "1.1.1"
                },
                {
                    "introduced": "1.1.2"
                },
                {
                    "last_affected": "1.1.2"
                },
                {
                    "introduced": "1.1.7"
                },
                {
                    "last_affected": "1.1.7"
                },
                {
                    "introduced": "1.1.8"
                },
                {
                    "last_affected": "1.1.8"
                },
                {
                    "introduced": "1.1.10"
                },
                {
                    "last_affected": "1.1.10"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18998.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-266",
        "CWE-285"
    ]
}
References

Affected packages

Git / github.com/cosmicstack-labs/mercury-agent

Affected ranges

Type
GIT
Repo
https://github.com/cosmicstack-labs/mercury-agent
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.1.0"
        },
        {
            "last_affected": "1.1.0"
        },
        {
            "introduced": "1.1.3"
        },
        {
            "last_affected": "1.1.3"
        },
        {
            "introduced": "1.1.4"
        },
        {
            "last_affected": "1.1.4"
        },
        {
            "introduced": "1.1.5"
        },
        {
            "last_affected": "1.1.5"
        },
        {
            "introduced": "1.1.6"
        },
        {
            "last_affected": "1.1.6"
        },
        {
            "introduced": "1.1.9"
        },
        {
            "last_affected": "1.1.9"
        },
        {
            "introduced": "1.1.11"
        },
        {
            "last_affected": "1.1.11"
        },
        {
            "introduced": "1.1.12"
        },
        {
            "last_affected": "1.1.12"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.1.0
1.1.11
1.1.12
1.1.3
1.1.4
1.1.5
1.1.6
1.1.9
v1.*
v1.1.0
v1.1.11
v1.1.12
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18998.json"