Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component. | |
| Title | ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy | |
| First Time appeared |
Ag-ui-protocol
Ag-ui-protocol ag-ui |
|
| Weaknesses | CWE-346 CWE-942 |
|
| CPEs | cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ag-ui-protocol
Ag-ui-protocol ag-ui |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-16T13:15:16.227Z
Reserved: 2026-09-16T05:36:01.573Z
Link: CVE-2026-92359
No data.
Status : Received
Published: 2026-09-16T13:18:08.873
Modified: 2026-09-16T13:18:08.873
Link: CVE-2026-92359
No data.
OpenCVE Enrichment
No data.