Impact
A vulnerability exists in simular-AI Agent-S component Model-Generated GUI Action Execution Workflow, affecting all releases up to version 0.3.2. The flaw resides in the grounding.py module and can be manipulated to trigger a denial of service. An attacker can send crafted requests that cause unbounded resource consumption, rendering the affected component unresponsive. The issue is classified as a Resource Not Found weakness (CWE-404) and does not impact confidentiality or integrity.
Affected Systems
The product in question is simular-AI Agent-S, with vulnerable releases up to and including version 0.3.2 as identified by the CNA.
Risk and Exploitability
While the CVSS base score of 5.3 indicates moderate severity, the vulnerability is remotely exploitable and the exploit code is publicly available. The EPSS score is unknown, but the lack of a KEV listing suggests no confirmed field-of-view exploitation traffic yet. Administrators should not consider this a low‑risk event; the absence of a vendor patch and the persistence of the flaw make mitigation a priority.
OpenCVE Enrichment