CVE-2026-101100
Received Received - Intake

Incomplete Cleanup in ag-ui-protocol ag-ui Middleware

Vulnerability report for CVE-2026-101100, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be launched remotely. Upgrading to version 2026-09-08 is able to resolve this issue. This patch is called c346119fe870b70f5c19738ee5119f3e1456e59d. It is suggested to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ag-ui-protocol ag-ui to 2026-09-07 (inc)
ag-ui-protocol ag-ui to 2026-09-08 (exc)
ag-ui-protocol ag-ui *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in ag-ui-protocol ag-ui up to 2026-09-07, specifically in the FilterToolCallsMiddleware function of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts. It allows incomplete cleanup due to a manipulation, potentially leading to unintended behavior. The issue can be exploited remotely.

Detection Guidance

Detection requires checking if the affected ag-ui-protocol ag-ui version (up to 2026-09-07) is installed. Inspect the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts for the FilterToolCallsMiddleware function. No specific commands are provided in the context.

Impact Analysis

The vulnerability may allow attackers to manipulate the system, causing incomplete cleanup of data or operations. This could lead to unintended side effects, data corruption, or unauthorized actions depending on the system's use of the affected middleware.

Compliance Impact

The vulnerability does not directly impact GDPR or HIPAA compliance as it involves a technical flaw in middleware state management rather than data privacy or security controls. The issue causes functional disruptions by retaining blocked tool-call IDs across runs, which may lead to unintended tool call filtering but does not inherently violate data protection requirements.

Mitigation Strategies

Upgrade ag-ui-protocol ag-ui to version 2026-09-08 or later. Apply the patch c346119fe870b70f5c19738ee5119f3e1456e59d to resolve the incomplete cleanup issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101100. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart