CVE-2026-90811 | cosmicstack-labs mercury-agent up to 1.2.0 Shell Permission Manifest permissions.ts PermissionManager.checkShellCommand information disclosure (Issue 102)
A vulnerability classified as problematic was found in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manifest. Executing a manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2026-90811. The attack is restricted to local execution. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.