CVE-2026-101101Medium· 4.3▾ SunlitA vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitat…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101100Medium· 5.4A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07
CVE-2026-101099Medium· 4.3A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23
CVE-2026-101098Medium· 4.3A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23
CVE-2026-92362High· 7.3A vulnerability was detected in ag-ui-protocol ag-ui 1.0
CVE-2026-92363Medium· 4.3A flaw has been found in ag-ui-protocol ag-ui 1.0
CVE-2026-92361Medium· 4.3A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0