Junglewise Threat Intelligence

CVE-2026-90811: Cosmicstack Labs Mercury Agent shell permission bypass via wc

CVE-2026-90811 · Severity: low · CVSS 3.3 · Published 2026-09-14

Technologies: Cosmicstack Labs Mercury Agent. Vendors: Cosmicstack Labs.

Executive brief

Mercury Agent is an AI agent framework with permission controls for shell command execution. A flaw in the shell permission manifest allows attackers to bypass the approval system and disclose metadata for files outside the approved working directory by using the `wc --files0-from` flag with a crafted file list, even though the command itself appears to be a safe read-only operation.

Technical details

The vulnerability is a policy mismatch in the PermissionManager.checkShellCommand function in mercury-agent/src/capabilities/permissions.ts. The shell permission manifest auto-approves `wc *` as a safe read-only command, but the path containment check only scans literal path tokens in the command string and fails to inspect paths that will be dereferenced later at execution time. An attacker can craft a command like `wc --files0-from=list0.bin` where `list0.bin` contains NUL-separated absolute paths to out-of-scope files. The command bypasses approval and executes through execSync, leaking file metadata via the command output. This requires local execution and the ability to create or control a file within the current workspace. The vulnerability has been disclosed publicly with a proof-of-concept but the vendor has not responded.

Affected products

  • Cosmicstack Labs Mercury Agent up to 1.2.0

Timeline

  • 2026-09-14: disclosed
  • other: Public exploit available; vendor issue report filed but no response yet

References

Related threats