Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101100— ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup

Quick assessment

Affected
ag-ui-protocol ag-ui
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ag-ui-protocol ag-ui 2026-09-07 及之前版本中发现了一个漏洞。该漏洞影响组件“Middleware”中文件 里的 函数。执行特定操作可能导致清理不完整。该漏洞可从远程发起攻击。升级至版本 2026-09-08 可解决此问题。该补丁的哈希值为 c346119fe870b70f5c19738ee5119f3e1456e59d。建议受影响的组件升级到修复版本。

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProduct Version RangeStatus
ag-ui-protocol ag-ui 2026-09-07 affected
2026-09-08 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101100

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be launched remotely. Upgrading to version 2026-09-08 is able to resolve this issue. This patch is called c346119fe870b70f5c19738ee5119f3e1456e59d. It is suggested to upgrade the affected component.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
清理环节不完整
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ag-ui-protocol ag-ui 2026-09-07 cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-101100

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101100

请登录查看更多情报信息。

Other References for CVE-2026-101100 (7)

Same Patch Batch · ag-ui-protocol · 2026-09-28 · 4 CVEs total

CVE-2026-101098 4.3 MEDIUM ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption
CVE-2026-101099 4.3 MEDIUM ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition
CVE-2026-101101 4.3 MEDIUM ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception

IV. Related Vulnerabilities

V. Comments for CVE-2026-101100

No comments yet


Leave a comment