Description
A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Exploitation
Action: Apply Patch
AI Analysis

Impact

A flaw in the prepareRunAgentInput function of ag-ui’s Event Application Layer allows an attacker to manipulate the TEXT_MESSAGE_START argument, resulting in an origin validation error that can be exploited remotely. The vulnerability does not grant direct code execution according to the description, but it can break the security check that authorizes event requests, potentially allowing an attacker to submit unauthorized data or commands to the agent layer.

Affected Systems

The issue affects ag-ui-protocol ag-ui version 1.0. Only installations running this version are impacted.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate impact. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, with an attacker sending crafted inputs to the Event Application Layer to bypass origin validation.

Generated by OpenCVE AI on September 18, 2026 at 05:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for updates from ag-ui-protocol and apply the vendor’s official patch once the pull request is merged.
  • If a patch is not yet available, restrict or validate the TEXT_MESSAGE_START argument to accept only preapproved values, thereby restoring the missing origin check.
  • Continuously monitor the vendor’s issue tracker and security advisories for any new information or a released fix.

Generated by OpenCVE AI on September 18, 2026 at 05:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.
Title ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation
First Time appeared Ag-ui-protocol
Ag-ui-protocol ag-ui
Weaknesses CWE-345
CWE-346
CPEs cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
Vendors & Products Ag-ui-protocol
Ag-ui-protocol ag-ui
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Ag-ui-protocol Ag-ui
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:45:46.190Z

Reserved: 2026-09-16T05:36:05.161Z

Link: CVE-2026-92360

cve-icon Vulnrichment

Updated: 2026-09-22T15:10:07.631Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T13:18:09.087

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-92360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:30:04Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-346

    Origin Validation Error