在 ag-ui-protocol ag-ui(截至 2026 年 9 月 7 日版本)中发现了一个漏洞。该问题影响中间件(Middleware)组件中 legacy/convert.ts 文件里的 JSON.parse 函数。此漏洞可导致未捕获的异常。攻击者可通过远程方式利用该漏洞。建议升级至 2026 年 9 月 8 日或更高版本以修复此问题,对应补丁标识为 30f8c794d5b73df5c610153043db502b2cc106cc。建议升级受影响的组件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ag-ui-protocol | ag-ui | 2026-09-07 |
affected |
2026-09-08 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ag-ui-protocol | ag-ui | 2026-09-07 |
cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101100 | 5.4 MEDIUM | ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup |
| CVE-2026-101098 | 4.3 MEDIUM | ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption |
| CVE-2026-101099 | 4.3 MEDIUM | ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition |
No comments yet