Impact
The flaw resides in the AgentSquad.routeRequest routine of the Streaming Agent Response Workflow component. An attacker can craft requests that cause the routine to consume excessive CPU or memory, leading to degraded performance or service unavailability. The vulnerability is purely a resource exhaustion flaw; no code execution or privilege escalation is possible.
Affected Systems
Products affected are 2FastLabs agent-squad versions up to and including 1.1.4. Any installation of 1.1.4 or earlier that executes the orchestrator module is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via network access to the Streaming Agent Response Workflow endpoint. If the component is exposed to untrusted networks, repeated exploitation could exhaust resources and cause a denial‑of‑service condition.
OpenCVE Enrichment