CVE-2026-92184
Received Received - Intake

Server-Side Request Forgery in ag-ui-protocol ag-ui

Vulnerability report for CVE-2026-92184, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: VulDB

Description

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation of the argument Value results in server-side request forgery. The attack can be executed remotely. The patch is identified as bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. It is advisable to implement a patch to correct this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ag-ui-protocol ag-ui 0.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in ag-ui-protocol ag-ui 0.3.0. It allows attackers to manipulate the urllib.request.urlopen function to make unauthorized server-side requests. The flaw exists in the Multimodal Content component where the Value argument can be altered to access internal files or network endpoints via protocols like file:// or ftp://.

Detection Guidance

To detect this SSRF vulnerability, monitor for unusual outbound requests from your server, especially to internal or loopback addresses. Check logs for urllib.request.urlopen calls with suspicious URLs like file:// or ftp:// schemes. Use network monitoring tools to detect connections to private IP ranges (e.g., 127.0.0.1, 10.0.0.0/8, 192.168.0.0/16) or metadata endpoints (e.g., 169.254.169.254).

Commands to check for vulnerable code: grep -r "urllib.request.urlopen" /path/to/ag_ui_strands/utils.py or search for InputContentUrlSource.value in sdks/python/ag_ui/core/types.py. Review URL handling logic for lack of scheme or IP validation.

Impact Analysis

An attacker could exploit this to read sensitive local files such as /etc/passwd or credential files, probe internal network endpoints like 127.0.0.1 or cloud metadata services, and potentially access restricted resources. The vulnerability bypasses security layers during preprocessing, allowing unauthorized file access and internal network probing before model checks.

Compliance Impact

This SSRF vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Unauthorized file access or internal network probing may result in data breaches, non-compliance with access controls, and failure to protect confidential information.

Mitigation Strategies

Apply the patch bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189 immediately. Implement strict URL fetch policies to allow only HTTP/HTTPS schemes and block private/internal networks. Disable redirects or validate them strictly. Set response size limits and disable userinfo in URLs to prevent credential exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92184. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart