在 ag-ui-protocol 的 ag-ui 1.0 版本中发现了一个安全漏洞。该漏洞位于组件“SSE 客户端”中,影响文件 中的一个未知功能。攻击者可通过该缺陷进行资源消耗型攻击(如导致内存或 CPU 资源被大量占用)。此攻击可以远程执行。用于修复该问题的 Pull Request 正等待被接受合并。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ag-ui-protocol | ag-ui | 1.0 |
cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92362 | 7.3 HIGH | ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption |
| CVE-2026-92360 | 6.3 MEDIUM | ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validati |
| CVE-2026-92363 | 4.3 MEDIUM | ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption |
| CVE-2026-92359 | 3.1 LOW | ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy |
No comments yet