CVE-2026-92360: AG-UI-Protocol AG-UI

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.

Affected products

Published 2026-09-16. Last modified 2026-09-23.