Resource Consumption Vulnerability in simular-ai Agent-S OCR HTTP API
CVE-2026-84886

6.9MEDIUM

Key Information:

Vendor

Simular-ai

Status
Vendor
CVE Published:
2 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-84886?

A resource consumption vulnerability has been identified in simular-ai's Agent-S product, specifically in the OCR HTTP API's ImageData function within the gui_agents/s1/utils/ocr_server.py file. This vulnerability allows an attacker to manipulate the img_bytes argument, potentially leading to significant resource exhaustion. Attackers could execute this exploit remotely, making it a considerable threat. Although the vendor was notified of this issue, there has been no response regarding any remedial action.

Affected Version(s)

Agent-S 0.3.0

Agent-S 0.3.1

Agent-S 0.3.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

hackerguopeng (VulDB User)
VulDB CNA Team
.