What is CVE-2026-18997?
CVE-2026-18997 is an incorrect authorization vulnerability in the `Agent.handleBgCommand` function within `src/core/agent.ts` of cosmicstack-labs mercury-agent, affecting versions up to 1.1.12. This flaw could allow a remote attacker to execute background commands with improper permissions. Users should update to the latest version immediately.
Azərbaycanca: CVE-2026-18997, cosmicstack-labs mercury-agent proqramının 1.1.12 versiyasına qədər olan versiyalarında `src/core/agent.ts` faylındakı `Agent.handleBgCommand` funksiyasında səlahiyyət yoxlaması zəifliyidir. Bu zəiflik uzaqdan hücum edən şəxsə yanlış icazə ilə arxa plan əmrlərini icra etməyə imkan verə bilər. İstifadəçilərə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: cosmicstack-labs
FAQ2
Which versions of the software are affected by CVE-2026-18997?
This vulnerability affects versions up to 1.1.12 of the cosmicstack-labs mercury-agent.
What can a remote attacker achieve by exploiting CVE-2026-18997?
A remote attacker can execute background commands with improper permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.