在 ag-ui-protocol ag-ui 0.3.0 中发现了一个安全漏洞。受影响的组件是位于 文件中的 函数,该函数属于 CORS 中间件(CORSMiddleware)。该漏洞导致跨域策略过于宽松,允许不可信域名进行跨域请求。攻击者可以从远程发起攻击,但攻击复杂度较高,且可利用性被评估为“困难”。升级到 AGUI.Abstractions@0.0.6 版本即可修复此问题。对应的补丁提交为 。建议升级受影响组件以解决该漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ag-ui-protocol | ag-ui | 0.3.0 |
cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92362 | 7.3 HIGH | ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption |
| CVE-2026-92360 | 6.3 MEDIUM | ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validati |
| CVE-2026-92361 | 4.3 MEDIUM | ag-ui-protocol ag-ui SSE Client client.go resource consumption |
| CVE-2026-92363 | 4.3 MEDIUM | ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption |
No comments yet