Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/cosmicstack-labs/mercury-agent

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability exists in cosmicstack-labs mercury-agent versions up to 1.1.13 in the checkShellCommand function, where validation occurs before canonicalization. This flaw could allow remote attackers to manipulate shell command execution order. The vulnerability has a low severity score and public exploit code is available. The project has been notified but has not yet responded or issued a fix.

Join the discussion

A security vulnerability (CVE-2026-90812) exists in cosmicstack-labs mercury-agent up to version 1.2.0. It affects the checkShellCommand function in the Shell Command Permission component, leading to incorrect privilege assignment. The vulnerability can be exploited remotely. The issue was reported early but the project has not yet responded or issued a fix. The CVSS score is 4.3, indicating a low severity impact.

Join the discussion

A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component GitHub API Handler. This manipulation of the argument path causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manifest. Executing a manipulation can lead to information disclosure. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

CVE-2026-18998 is a medium severity vulnerability in cosmicstack-labs mercury-agent up to version 1.1.12. It affects the SubAgent.run function in the delegate_task Tool component, allowing improper authorization through remote manipulation. The vulnerability has been publicly disclosed, but no official fix or response from the vendor has been reported yet.

Join the discussion

A vulnerability in cosmicstack-labs mercury-agent up to version 1.1.12 allows remote attackers to cause incorrect authorization via manipulation of the Agent.handleBgCommand function. The issue affects the background command handler component and could lead to limited confidentiality, integrity, and availability impacts. The vulnerability has a CVSS score of 6.3 and is classified as low severity. No patch or official fix has been reported yet, and the project has not responded to the issue report. Exploit code has been made public, but no known exploitation in the wild has been confirmed.

Join the discussion

CVE-2026-18997 is a medium severity vulnerability in cosmicstack-labs mercury-agent up to version 1.1.12. It involves incorrect authorization in the Agent.handleBgCommand function, allowing remote attackers to manipulate background commands without proper authorization. The vulnerability has a CVSS 4.0 base score of 5.3. The project has been informed but has not yet responded or issued a fix. Exploit code has been publicly disclosed, but no known active exploitation in the wild is reported.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Package: pkg:github/cosmicstack-labs/mercury-agent
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses