Description
A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability was discovered in the CodeAgent component of simular‑ai Agent‑S, affecting an unspecified function within code_agent.py. Manipulating this function can trigger a denial of service that leaves the target application or service unresponsive. The flaw is classified as CWE‑404, indicating that unused or unnecessary functionality can be abused. Attackers can launch the exploit remotely, and the vulnerability has already been publicly disclosed, creating a real risk of service disruption.

Affected Systems

All installations of simular‑ai Agent‑S version 0.3.1 and 0.3.2 that include the CodeAgent component are impacted. Networks or environments that use the code_agent.py file are directly vulnerable. No other versions or unrelated components are known to be affected.

Risk and Exploitability

The CVSS score of 5.3 signals a medium severity. Though the EPSS score is not available, the public disclosure and lack of vendor response create a moderate risk of exploitation. The flaw can be triggered remotely, potentially causing service downtime. The vulnerability is not yet listed in CISA KEV, but the combination of public knowledge and absence of a fix widens the exploitation window.

Generated by OpenCVE AI on September 3, 2026 at 09:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Agent‑S as soon as it is released by the vendor.
  • If upgrading is not possible, remove or disable the vulnerable function or the code_agent.py component when the functionality is not required.
  • Implement network‑level filtering or rate limiting on the endpoints that invoke CodeAgent to mitigate repeated DoS attempts.
  • Monitor application logs for abnormal patterns or repeated failures that may indicate exploitation attempts.

Generated by OpenCVE AI on September 3, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title simular-ai Agent-S CodeAgent code_agent.py denial of service
First Time appeared Simular-ai
Simular-ai agent-s
Weaknesses CWE-404
CPEs cpe:2.3:a:simular-ai:agent-s:*:*:*:*:*:*:*:*
Vendors & Products Simular-ai
Simular-ai agent-s
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Simular-ai Agent-s
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-03T13:34:41.362Z

Reserved: 2026-09-02T14:16:00.952Z

Link: CVE-2026-84885

cve-icon Vulnrichment

Updated: 2026-09-03T13:34:36.287Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T05:16:47.010

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T09:45:03Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release