Impact
A vulnerability was discovered in the CodeAgent component of simular‑ai Agent‑S, affecting an unspecified function within code_agent.py. Manipulating this function can trigger a denial of service that leaves the target application or service unresponsive. The flaw is classified as CWE‑404, indicating that unused or unnecessary functionality can be abused. Attackers can launch the exploit remotely, and the vulnerability has already been publicly disclosed, creating a real risk of service disruption.
Affected Systems
All installations of simular‑ai Agent‑S version 0.3.1 and 0.3.2 that include the CodeAgent component are impacted. Networks or environments that use the code_agent.py file are directly vulnerable. No other versions or unrelated components are known to be affected.
Risk and Exploitability
The CVSS score of 5.3 signals a medium severity. Though the EPSS score is not available, the public disclosure and lack of vendor response create a moderate risk of exploitation. The flaw can be triggered remotely, potentially causing service downtime. The vulnerability is not yet listed in CISA KEV, but the combination of public knowledge and absence of a fix widens the exploitation window.
OpenCVE Enrichment