Impact
The flaw resides in the create_strands_app function within the CORSMiddleware component of ag-ui 0.3.0. It causes the application to return a CORS policy that allows any origin, thereby permitting requests from untrusted domains. The impact is the exposure of protected resources and the potential for cross‑site request forgery or data exfiltration by remote actors. The CVE notes that the attack may be launched remotely, requires a high level of complexity, and the exploitability is described as difficult.
Affected Systems
Affected systems are the ag-ui application from ag-ui-protocol, specifically version 0.3.0. No other versions are reported as vulnerable.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score of < 1% shows a very low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would involve a remote attacker sending crafted HTTP requests that trigger the permissive CORS response, enabling malicious cross‑domain interactions. Overall risk is low but the presence of a remote attack vector warrants timely remediation.
OpenCVE Enrichment