CVE-2026-90810

Source
https://cve.org/CVERecord?id=CVE-2026-90810
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90810.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90810
Published
2026-09-14T18:30:08Z
Modified
2026-09-17T03:30:39Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
cosmicstack-labs mercury-agent Shell Command Permission Check permissions.ts PermissionManager.checkShellCommand improper authorization
Details

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-266",
        "CWE-285"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90810.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.1.1"
                },
                {
                    "last_affected": "1.1.1"
                },
                {
                    "introduced": "1.1.2"
                },
                {
                    "last_affected": "1.1.2"
                },
                {
                    "introduced": "1.1.7"
                },
                {
                    "last_affected": "1.1.7"
                },
                {
                    "introduced": "1.1.8"
                },
                {
                    "last_affected": "1.1.8"
                },
                {
                    "introduced": "1.1.10"
                },
                {
                    "last_affected": "1.1.10"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/cosmicstack-labs/mercury-agent

Affected ranges

Type
GIT
Repo
https://github.com/cosmicstack-labs/mercury-agent
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.1.0"
        },
        {
            "last_affected": "1.1.0"
        },
        {
            "introduced": "1.1.3"
        },
        {
            "last_affected": "1.1.3"
        },
        {
            "introduced": "1.1.4"
        },
        {
            "last_affected": "1.1.4"
        },
        {
            "introduced": "1.1.5"
        },
        {
            "last_affected": "1.1.5"
        },
        {
            "introduced": "1.1.6"
        },
        {
            "last_affected": "1.1.6"
        },
        {
            "introduced": "1.1.9"
        },
        {
            "last_affected": "1.1.9"
        },
        {
            "introduced": "1.1.11"
        },
        {
            "last_affected": "1.1.11"
        },
        {
            "introduced": "1.1.12"
        },
        {
            "last_affected": "1.1.12"
        },
        {
            "introduced": "1.1.13"
        },
        {
            "last_affected": "1.1.13"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.1.0
1.1.11
1.1.12
1.1.13
1.1.3
1.1.4
1.1.5
1.1.6
1.1.9
v1.*
v1.1.0
v1.1.11
v1.1.12
v1.1.13
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90810.json"