Cross-Domain Policy Vulnerability in ag-ui-protocol ag-ui
CVE-2026-92359
2.3LOW
What is CVE-2026-92359?
A security flaw in the ag-ui-protocol's ag-ui version 0.3.0 has been identified, specifically within the create_strands_app function of the CORSMiddleware component. This flaw allows for the creation of a permissive cross-domain policy that may inadvertently trust unverified domains. Attackers could exploit this issue remotely, presenting a significant risk to data integrity and confidentiality. The complexity of the attack is notably high, making the vulnerability particularly challenging to exploit. Users are strongly advised to upgrade to version AGUI.Abstractions@0.0.6 to mitigate this risk, as the patch is encapsulated in commit 9b143b9668fa52c2054ede9d34a45ac4b4401089.
Affected Version(s)
ag-ui 0.3.0
ag-ui AGUI.Abstractions@0.0.6
