CVE-2026-101100: ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup
A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be launched remotely. Upgrading to version 2026-09-08 is able to resolve this issue. This patch is called c346119fe870b70f5c19738ee5119f3e1456e59d. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ag-ui-protocol ag-uito a version that resolves this vulnerability.Fixed in 2026-09-08Patch c346119fe870b70f5c19738ee5119f3e1456e59d
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using ag-ui-protocol ag-ui versions up to 2026-09-07 are affected if they include the Middleware component's FilterToolCallsMiddleware implementation in sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts.
What level of access does an attacker need?
The issue can be exploited remotely and has low attack complexity, but the vector indicates that the attacker needs low-level privileges. No user interaction is required.
What is the impact of successful exploitation?
Successful manipulation can cause incomplete cleanup. The reported impact is limited to integrity and availability; no confidentiality impact is identified.
How should this be remediated?
Upgrade ag-ui-protocol ag-ui to version 2026-09-08. The referenced fix is commit c346119fe870b70f5c19738ee5119f3e1456e59d.