Server-Side Request Forgery Vulnerability in ag-ui-protocol Multimodal Content
CVE-2026-92184

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92184?

A security flaw in the ag-ui-protocol ag-ui version 0.3.0 has been identified, specifically within the function urllib.request.urlopen located in the file integrations/aws-strands/python/src/ag_ui_strands/utils.py. This vulnerability enables an external attacker to manipulate the Value argument to perform a server-side request forgery (SSRF) attack. Such an attack can compromise the integrity of the server by allowing unauthorized requests to be made, which could potentially lead to exposure of sensitive information or further attacks. The issue can be patched using the identified fix in commit bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189.

Affected Version(s)

ag-ui 0.3.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

colorfullbz (VulDB User)
.