在 simular-ai Agent-S(版本 0.3.2 及以下)中发现了一个安全漏洞。 受此问题影响的是组件“模型生成的 GUI 动作执行工作流”中文件 中某个未明确说明的功能。攻击者可通过操作该功能导致服务中断(拒绝服务,DoS)。该漏洞可被远程利用。利用代码(Exploit)已公开,且可能被实际使用。研究方曾提前联系供应商披露此事,但供应商未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| simular-ai | Agent-S | 0.3.0 |
cpe:2.3:a:simular-ai:agent-s:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84886 | 5.3 MEDIUM | simular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumption |
| CVE-2026-84885 | 4.3 MEDIUM | simular-ai Agent-S CodeAgent code_agent.py denial of service |
No comments yet