{"vuid":"VU#212479","idnumber":"212479","name":"Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment","keywords":null,"overview":"### Overview\r\nA vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as **CVE-2026-90999**.\r\n\r\n### Description\r\nSentry is a software error‑monitoring and performance‑tracking platform used by developers to detect, diagnose, and understand issues in their applications. It collects telemetry such as exceptions, stack traces, logs, and performance data from applications. Built into Sentry, Seer acts as an automated debugging assistant that converts telemetry into actionable remediation steps and can hand off issues to an integrated coding agent to propose code fixes.\r\n\r\nBecause Sentry front-end projects commonly expose a public DSN (Data Source Name) to allow browsers to submit this telemetry, an attacker can craft and submit malicious events through this public endpoint. When Seer is enabled to automatically pass issues to a coding agent, these attacker-supplied events can traverse multiple trust boundaries. Ultimately, malicious event fields propagate through Seer’s analysis pipeline, transforming into untrusted instructions that the privileged coding agent may execute.\r\n\r\nThe vulnerable workflow is as follows:\r\n* Sentry ingests attacker‑generated exception events submitted through the public DSN.\r\n* Seer evaluates whether the event represents an issue eligible for automated remediation.\r\n* Seer generates a root‑cause analysis that uses attacker-controlled event fields, including exception messages, stack traces, source context, and breadcrumbs.\r\n* The generated analysis is embedded directly into the initial prompt provided to the coding agent.\r\n* The coding agent interprets the fabricated analysis as a legitimate description of the victim’s codebase.\r\n* During its investigation, the coding agent downloads and executes a package controlled by the attacker.\r\n* The package executes within the coding‑agent environment prior to any human review of a pull request.\r\n\r\n### Impact\r\nSuccessful exploitation may allow arbitrary code execution in the coding‑agent environment that processes the affected repository. \r\n\r\n### Solution\r\nAt the time of this writing, no vendor‑supplied patch information has been provided. Mitigations may include disabling automated remediation flows, restricting coding‑agent package installation, or disabling Seer handoff until a fix is available. Additional defensive filtering of telemetry content before Seer analysis may also reduce risk.\r\n\r\n### Acknowledgements\r\nThank you to Nikita Benkovich and Vitalii Valkov, agyn for reporting this vulnerability. This document was written by Bob Kemerer.","clean_desc":null,"impact":null,"resolution":null,"workarounds":null,"sysaffected":null,"thanks":null,"author":null,"public":[],"cveids":["CVE-2026-90999"],"certadvisory":null,"uscerttechnicalalert":null,"datecreated":"2026-09-16T15:18:04.321146Z","publicdate":"2026-09-16T15:18:04.070503Z","datefirstpublished":"2026-09-16T15:18:04.354700Z","dateupdated":"2026-09-16T15:18:04.070499Z","revision":1,"vrda_d1_directreport":null,"vrda_d1_population":null,"vrda_d1_impact":null,"cam_widelyknown":null,"cam_exploitation":null,"cam_internetinfrastructure":null,"cam_population":null,"cam_impact":null,"cam_easeofexploitation":null,"cam_attackeraccessrequired":null,"cam_scorecurrent":null,"cam_scorecurrentwidelyknown":null,"cam_scorecurrentwidelyknownexploited":null,"ipprotocol":null,"cvss_accessvector":null,"cvss_accesscomplexity":null,"cvss_authentication":null,"cvss_confidentialityimpact":null,"cvss_integrityimpact":null,"cvss_availabilityimpact":null,"cvss_exploitablity":null,"cvss_remediationlevel":null,"cvss_reportconfidence":null,"cvss_collateraldamagepotential":null,"cvss_targetdistribution":null,"cvss_securityrequirementscr":null,"cvss_securityrequirementsir":null,"cvss_securityrequirementsar":null,"cvss_basescore":null,"cvss_basevector":null,"cvss_temporalscore":null,"cvss_environmentalscore":null,"cvss_environmentalvector":null,"metric":null,"vulnote":246}