Impact
The vulnerability resides in simular-ai’s Agent-S OCR HTTP API, specifically the ImageData function that accepts img_bytes. An attacker who sends a carefully crafted image payload can cause the server to consume excessive CPU or memory, leading to degraded performance or service interruption. This weakness falls under CWE-400 (Uncontrolled Resource Consumption) and CWE-404, and the official description calls it a resource consumption issue that can be exploited remotely. The impact is loss of availability for clients relying on the OCR service.
Affected Systems
The flaw affects simular-ai Agent-S versions up to and including 0.3.2. Administrators managing this product should verify that their deployment is within that range and look for any subsequent releases that address the issue. No other products or vendors are listed as affected in the CNA data.
Risk and Exploitability
The CVSS v3 base score of 6.9 indicates a medium severity threat, and the absence of an EPSS score means the exploit probability is currently unknown. Because the attack vector is described as remote and the vulnerability is exposed via an HTTP API, the potential for widespread exploitation exists if further workarounds remain available. The vulnerability is not yet catalogued in CISA’s KEV list, but given the public disclosure and lack of vendor response, it represents a realistic risk of denial of service in operational environments.
OpenCVE Enrichment