Impact
A flaw in the prepareRunAgentInput function of ag-ui’s Event Application Layer allows an attacker to manipulate the TEXT_MESSAGE_START argument, resulting in an origin validation error that can be exploited remotely. The vulnerability does not grant direct code execution according to the description, but it can break the security check that authorizes event requests, potentially allowing an attacker to submit unauthorized data or commands to the agent layer.
Affected Systems
The issue affects ag-ui-protocol ag-ui version 1.0. Only installations running this version are impacted.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate impact. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, with an attacker sending crafted inputs to the Event Application Layer to bypass origin validation.
OpenCVE Enrichment