Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92359— ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy

Quick assessment

Affected
ag-ui-protocol ag-ui
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ag-ui-protocol ag-ui 0.3.0 中发现了一个安全漏洞。受影响的组件是位于 文件中的 函数,该函数属于 CORS 中间件(CORSMiddleware)。该漏洞导致跨域策略过于宽松,允许不可信域名进行跨域请求。攻击者可以从远程发起攻击,但攻击复杂度较高,且可利用性被评估为“困难”。升级到 AGUI.Abstractions@0.0.6 版本即可修复此问题。对应的补丁提交为 。建议升级受影响组件以解决该漏洞。

CVSS 3.1 · Low
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92359

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy
Source: CVE Program / CVE List V5
Vulnerability Description
A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
过度许可的跨域白名单
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ag-ui-protocol ag-ui 0.3.0 cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-92359

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92359

登录查看更多情报信息。

Patches & Fixes for CVE-2026-92359 (1)

Vendor Pages for CVE-2026-92359 (1)

Other References for CVE-2026-92359 (1)

Same Patch Batch · ag-ui-protocol · 2026-09-16 · 5 CVEs total

CVE-2026-92362 7.3 HIGH ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption
CVE-2026-92360 6.3 MEDIUM ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validati
CVE-2026-92361 4.3 MEDIUM ag-ui-protocol ag-ui SSE Client client.go resource consumption
CVE-2026-92363 4.3 MEDIUM ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption

IV. Related Vulnerabilities

V. Comments for CVE-2026-92359

No comments yet


Leave a comment