CVE-2026-90813 Details
Description
A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in Cosmicstack Labs Mercury-Agent versions up to 1.1.13, specifically within the Shell Command Execution component. The issue arises in the checkShellCommand function, where the order of validation and canonicalization is flawed. This flaw allows commands that reference files in the home directory to bypass intended workspace boundaries, enabling unauthorized access to local files without triggering the necessary approval prompts. The vulnerability can be exploited remotely, and the details of the exploit are publicly available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cosmicstack-labs/mercury-agent/ | [email protected] | Vendor |
| https://github.com/cosmicstack-labs/mercury-agent/issues/95 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://vuldb.com/cve/CVE-2026-90813 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/922879 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403315 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403315/cti | [email protected] | AdvisoryContent Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-179 | Incorrect Behavior Order: Early Validation | [email protected] |
| CWE-180 | Incorrect Behavior Order: Validate Before Canonicalize | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cosmicstack-labs mercury-agent | <= 1.1.13 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | New CVE Received | [email protected] |
| Sep 14, 2026 | CVE Modified | CISA-ADP |
Volerion