VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Imported from official source

Advisory

Cybersecurity Classified by Officially

A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999.

Sentry is a software error‑monitoring and performance‑tracking platform used by developers to detect, diagnose, and understand issues in their applications. It collects telemetry such as exceptions, stack traces, logs, and performance data from applications. Built into Sentry, Seer acts as an automated debugging assistant that converts telemetry into actionable remediation steps and can hand off issues to an integrated coding agent to propose code fixes.

Because Sentry front-end projects commonly expose a public DSN (Data Source Name) to allow browsers to submit this telemetry, an attacker can craft and submit malicious events through this public endpoint. When Seer is enabled to automatically pass issues to a coding agent, these attacker-supplied events can traverse multiple trust boundaries. Ultimately, malicious event fields propagate through Seer’s analysis pipeline, transforming into untrusted instructions that the privileged coding agent may execute.

This is an extract. The publication continues at the source.

Read the original at the source: https://kb.cert.org/vuls/id/212479

Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

3 versions recorded. The original is kept in full — nothing is overwritten.

  1. v3 imported change on current
  2. v2 imported change on
  3. v1 as first published on

Provenance

Organization
CERT Coordination Center — imported from official source
Official source
https://www.kb.cert.org/vuls/atomfeed/ ATOM
Imported
September 16, 2026 15:30
Versions
3 recorded
Identity
https://kb.cert.org/vuls/id/212479

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.