CVE-2026-85100
Received Received - Intake

Resource Exhaustion in 2FastLabs Agent-Squad

Vulnerability report for CVE-2026-85100, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulDB

Description

A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component Streaming Agent Response Workflow. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
2fastlabs agent-squad to 1.1.4 (inc)
2fastlabs agent_squad 1.1.4
2fastlabs agent_squad to 1.1.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in 2FastLabs agent-squad up to version 1.1.4. It affects the AgentSquad.routeRequest function in the agent-squad/typescript/src/orchestrator.ts file, specifically in the Streaming Agent Response Workflow component. The issue leads to resource consumption and can be exploited remotely. The exploit is public, and the vendor has not responded to the reported issue.

Impact Analysis

This vulnerability may cause resource exhaustion on affected systems, potentially leading to degraded performance or service disruption. Since it can be exploited remotely, unauthorized users might consume system resources without authentication, impacting availability.

Mitigation Strategies

Update the 2FastLabs agent-squad software to the latest version beyond 1.1.4 if available. If no update is available, consider disabling the affected component or restricting network access to it until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85100. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart