CVE-2026-90813
CVE-2026-90813 is a medium-severity vulnerability with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-179.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v2: 4.0
- CVSS v4: 2.1
- EPSS exploit prediction: 1% (44th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-179
- Published:
- Last modified:
Description
A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Frequently asked questions
- What is CVE-2026-90813?
- A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
- How severe is CVE-2026-90813?
- CVE-2026-90813 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2026-90813 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (44th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-90813?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-90813 published?
- CVE-2026-90813 was published on 2026-09-14.
References
- https://github.com/cosmicstack-labs/mercury-agent/
- https://github.com/cosmicstack-labs/mercury-agent/issues/95
- https://vuldb.com/cve/CVE-2026-90813
- https://vuldb.com/submit/922879
- https://vuldb.com/vuln/403315
- https://vuldb.com/vuln/403315/cti
Other CWE-179 vulnerabilities
- CVE-2025-4759 — High (CVSS 8.3): Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via…
- CVE-2026-49414 — High (CVSS 7.8): The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the…
- CVE-2026-3832 — Low (CVSS 3.7): A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online…
- CVE-2024-41686 — Low (CVSS 3.3): This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A…