The CVE-2026-18998 vulnerability was determined in cosmicstack-labs mercury-agent up to version 1.1.12, impacting the SubAgent.run function in src/core/sub-agent.ts, potentially leading to improper authorization. This vulnerability has a low CVSS score of 2.1 and is considered a low-priority defensive review. Users of cosmicstack-labs mercury-agent up to version 1.1.12 should review and verify the vulnera [truncated]
The CVE-2026-18997 vulnerability affects cosmicstack-labs mercury-agent up to version 1.1.12, specifically in the Agent.handleBgCommand function within the src/core/agent.ts file. This issue results in incorrect authorization, allowing for remote attacks. The vulnerability has been made public, and although details about the exploit and affected scope are limited, users of the affected product should be a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T05:16:42.087Z and has not been modified since then. The vulnerability affects cosmicstack-labs mercury-agent up to version 1.1.12, specifically the PermissionManager.checkShellCommand function, leading to incorrect privilege assignment. The attack may be performed from remote. The exploit has bee [truncated]