Impact
A flaw in ag-ui-protocol ag-ui 0.3.0 allows an attacker to manipulate the URL argument passed to urllib.request.urlopen within the Multimodal Content utilities. This manipulation enables a server‑side request forgery that can be triggered remotely, potentially allowing the attacker to force the application to make arbitrary outbound network requests. The vulnerability does not provide direct code execution but can be abused to exfiltrate data, pivot to internal resources, or disrupt services via expanded network connectivity.
Affected Systems
Affected products are the ag-ui component supplied by ag‑ui‑protocol. The vulnerability is present in release 0.3.0 and earlier versions that have not applied the referenced patch commit bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. No other vendor or product is listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not catalogued in the CISA KEV list. Exploitation requires remote access to the application and the ability to supply a crafted URL; no privileged or local execution is required. The straightforward attack vector is through the exposed URL parameter, making it a typical SSRF risk that can be mitigated with proper input validation or network controls.
OpenCVE Enrichment