CVE-2026-90814 | cosmicstack-labs mercury-agent up to 1.1.13 GitHub API src/utils/github.ts githubRequest path server-side request forgery (Issue 81)
A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.13 and classified as critical. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component GitHub API Handler. This manipulation of the argument path causes server-side request forgery.
This vulnerability is registered as CVE-2026-90814. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.