A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin valida
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ag-ui-protocol | ag-ui | 1.0 |
cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92362 | 7.3 HIGH | ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption |
| CVE-2026-92361 | 4.3 MEDIUM | ag-ui-protocol ag-ui SSE Client client.go resource consumption |
| CVE-2026-92363 | 4.3 MEDIUM | ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption |
| CVE-2026-92359 | 3.1 LOW | ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy |
No comments yet