PatchSiren

cosmicstack-labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW cosmicstack-labs CVE published 2026-08-06

CVE-2026-18998

The CVE-2026-18998 vulnerability was determined in cosmicstack-labs mercury-agent up to version 1.1.12, impacting the SubAgent.run function in src/core/sub-agent.ts, potentially leading to improper authorization. This vulnerability has a low CVSS score of 2.1 and is considered a low-priority defensive review. Users of cosmicstack-labs mercury-agent up to version 1.1.12 should review and verify the vulnera [truncated]

LOW cosmicstack-labs CVE published 2026-08-06

CVE-2026-18997

The CVE-2026-18997 vulnerability affects cosmicstack-labs mercury-agent up to version 1.1.12, specifically in the Agent.handleBgCommand function within the src/core/agent.ts file. This issue results in incorrect authorization, allowing for remote attacks. The vulnerability has been made public, and although details about the exploit and affected scope are limited, users of the affected product should be a [truncated]

LOW cosmicstack-labs CVE published 2026-08-06

CVE-2026-18996

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T05:16:42.087Z and has not been modified since then. The vulnerability affects cosmicstack-labs mercury-agent up to version 1.1.12, specifically the PermissionManager.checkShellCommand function, leading to incorrect privilege assignment. The attack may be performed from remote. The exploit has bee [truncated]