Impact
This vulnerability originates in the SSE Client of ag-ui version 1.0, where manipulation of an unknown function in client.go can drain system resources. The effect is a denial of service caused by uncontrolled resource consumption, as identified by CWE-400, and involves improper error handling or path resolution identified by CWE-404. The description indicates that the attack vector is remote, implying that a network attacker can trigger the exploit without local access.
Affected Systems
Vendor ag-ui-protocol offers the affected product ag-ui, version 1.0. No other versions are listed in the CVE record.
Risk and Exploitability
The CVSS score of 5.3 suggests moderate severity, and an EPSS score of less than 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The remote nature of the attack and the lack of a public patch mean that immediate exploitation poses limited risk, but the potential for resource exhaustion remains if the vulnerability remains unpatched.
OpenCVE Enrichment