在 cosmicstack-labs 的 mercury-agent(版本 1.1.13 及更早版本)中发现了一个缺陷。该漏洞影响了 GitHub API 处理器组件中 文件中的 函数。由于对参数 的操作不当,导致了服务端请求伪造(SSRF, Server-Side Request Forgery)漏洞。该漏洞可被远程利用,且利用方式已公开,可能被攻击者使用。项目方虽已较早通过问题报告获悉此问题,但至今未作回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cosmicstack-labs | mercury-agent | 1.1.0 |
cpe:2.3:a:cosmicstack-labs:mercury-agent:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90810 | 6.3 MEDIUM | cosmicstack-labs mercury-agent Shell Command Permission Check permissions.ts PermissionMan |
| CVE-2026-90812 | 4.3 MEDIUM | cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkShellCommand p |
| CVE-2026-90813 | 4.3 MEDIUM | cosmicstack-labs mercury-agent Shell Command Execution permissions.ts checkShellCommand va |
| CVE-2026-90811 | 3.3 LOW | cosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts PermissionManager. |
No comments yet