PT-2026-93825 · Sentry · Sentry Seer
CVE-2026-90999
·
Published
2026-09-16
·
Updated
2026-09-26
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sentry Seer (affected versions not specified)
Description
Sentry Seer is subject to a multi-stage trust-boundary violation where unauthenticated telemetry input can be executed as code within a privileged automation environment. The issue occurs when a project uses a public DSN (Data Source Name), which is an identifier used by Sentry to route events to the correct project. An external attacker can submit fabricated exception events to this public endpoint without requiring an account or access to the victim's infrastructure.
If the Seer auto-remediation feature is enabled, these attacker-controlled fields—including the exception message, stack trace, source context, and breadcrumbs—are used to generate a root-cause analysis. This analysis is then passed as a trusted instruction to a coding agent (such as Claude, Cursor Cloud, or Copilot Cloud). The agent may then fetch and execute attacker-controlled code or install malicious packages within its environment. Because the agent typically holds the project's source code and credentials for connected repositories, the attacker can read, modify, and push code to those repositories.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Disable the automatic handoff of issues from Sentry Seer to coding agents.
Prevent coding agents from installing packages autonomously.
Manually review all events before allowing any remediation action.
RCE
Code Injection
Special Elements Injection
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sentry Seer