PT-2026-68381 · Cosmicstack · Mercury-Agent

·

CVE-2026-18997

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cosmicstack-labs mercury-agent versions prior to 1.1.13
Description An issue in the bg Command Handler component allows for incorrect authorization through manipulation. This can be triggered remotely via the Agent.handleBgCommand() function located in the src/core/agent.ts file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Agent.handleBgCommand() function to minimize the risk of exploitation.

Exploit

Improper Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18997

Affected Products

Mercury-Agent