MEDIUM

CVE-2026-92360

2026-09-16 CVSS v3.1
CVSS
6.3

Description

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.

Weakness (CWE)

CWE-345
CWE-346

EPSS Score

0.18%
Probability of exploitation in next 30 days
7.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE