cosmicstack-labs vulnerabilities
3 CVEs tracked
Cosmicstack-labs appears in recent reporting due to multiple critical vulnerabilities identified in their 'mercury-agent' product (versions ≤1.1.12). The main theme involves improper authorization and privilege management issues affecting the agent's core command execution and task delegation functions. Defenders should prioritize attention to CVE-2026-18996 (incorrect privilege assignment in run_command handler), CVE-2026-18997 (incorrect authorization in bg Command Handler), and CVE-2026-18998 (improper authorization in delegate_task Tool), and ensure immediate patching for systems running versions up to 1.1.12.
Azərbaycanca: Cosmicstack-labs son hesabatlarda 'mercury-agent' məhsulunda (≤1.1.12 versiyaları) aşkarlanmış bir neçə kritik zəifliklə əlaqədar görünür. Əsas mövzu düzgün olmayan icazə yoxlamaları (authorization) və imtiyaz (privilege) idarəetməsidir ki, bu da agentin əsas əmr icra və tapşırıq ötürmə funksiyalarına təsir edir. Müdafiəçilər xüsusilə CVE-2026-18996 (run_command handler-da səhv imtiyaz təyinatı), CVE-2026-18997 (bg Command Handler-da yanlış icazə) və CVE-2026-18998 (delegate_task alətində düzgün olmayan icazələndirmə) zəifliklərinə diqqət yetirməli və 1.1.12 versiyasına qədər olan sistemlərin təcili yenilənməsini təmin etməlidir.
This vendor's CVEs3
This hub is built from skopnix's own reporting on cosmicstack-labs: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.