在 ag-ui-protocol 的 ag-ui 组件(截至 2026-09-23 的版本)中发现了一个漏洞。该漏洞影响 Kotlin Community SDK 中 SseParser.kt 文件的未知部分。对该部分进行操纵会导致异常条件的处理问题。攻击者可远程发起此类攻击。修复该问题的拉取请求(Pull Request)目前正等待接受。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ag-ui-protocol | ag-ui | 2026-09-23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ag-ui-protocol | ag-ui | 2026-09-23 |
cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101100 | 5.4 MEDIUM | ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup |
| CVE-2026-101098 | 4.3 MEDIUM | ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption |
| CVE-2026-101101 | 4.3 MEDIUM | ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception |
No comments yet