Cross-Domain Policy Vulnerability in ag-ui-protocol ag-ui
CVE-2026-92359

2.3LOW

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92359?

A security flaw in the ag-ui-protocol's ag-ui version 0.3.0 has been identified, specifically within the create_strands_app function of the CORSMiddleware component. This flaw allows for the creation of a permissive cross-domain policy that may inadvertently trust unverified domains. Attackers could exploit this issue remotely, presenting a significant risk to data integrity and confidentiality. The complexity of the attack is notably high, making the vulnerability particularly challenging to exploit. Users are strongly advised to upgrade to version AGUI.Abstractions@0.0.6 to mitigate this risk, as the patch is encapsulated in commit 9b143b9668fa52c2054ede9d34a45ac4b4401089.

Affected Version(s)

ag-ui 0.3.0

ag-ui AGUI.Abstractions@0.0.6

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

colorfullbz (VulDB User)
.