Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance. | |
| Title | ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation | |
| First Time appeared |
Ag-ui-protocol
Ag-ui-protocol ag-ui |
|
| Weaknesses | CWE-345 CWE-346 |
|
| CPEs | cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ag-ui-protocol
Ag-ui-protocol ag-ui |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-16T12:30:09.510Z
Reserved: 2026-09-16T05:36:05.161Z
Link: CVE-2026-92360
No data.
Status : Received
Published: 2026-09-16T13:18:09.087
Modified: 2026-09-16T13:18:09.087
Link: CVE-2026-92360
No data.
OpenCVE Enrichment
No data.