在 simular-ai 的 Agent-S(版本 ≤ 0.3.2)中已发现一个安全漏洞。该漏洞影响了组件“OCR HTTP API”中文件 内的 函数。攻击者可以通过操纵参数 来触发资源消耗问题(例如内存或 CPU 过度占用),从而导致服务性能下降或不可用。该攻击可远程发起,且相关利用方法已公开披露,可能被攻击者利用。供应商虽在漏洞披露初期已被联系,但未能作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| simular-ai | Agent-S | 0.3.0 |
cpe:2.3:a:simular-ai:agent-s:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84885 | 4.3 MEDIUM | simular-ai Agent-S CodeAgent code_agent.py denial of service |
| CVE-2026-84887 | 4.3 MEDIUM | simular-ai Agent-S Model-generated GUI Action Execution Workflow grounding.py denial of se |
No comments yet