Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization
Vulnerability Description
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
授权机制不恰当
Vulnerability Title
Cosmic Stack Mercury 权限许可和访问控制问题漏洞
Vulnerability Description
Cosmic Stack Mercury是Cosmic Stack组织的一个具备权限控制、长期记忆、Token预算管理和多渠道交互能力的AI智能体框架。 Cosmic Stack Mercury 1.1.12及之前版本存在安全漏洞,该漏洞源于delegate_task Tool组件中src/core/sub-agent.ts文件的SubAgent.run函数存在授权不当,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A