CVE-2026-101101: ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception
A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ag-ui-protocol ag-uito a version that resolves this vulnerability.Fixed in 2026-09-08Patch 30f8c794d5b73df5c610153043db502b2cc106cc
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attack can be conducted remotely and requires low privileges. No user interaction is required.
What is the expected security impact?
The reported impact is limited to availability: an attacker may trigger an uncaught exception. The provided severity vector indicates no confidentiality or integrity impact.
Which deployments should be upgraded?
Deployments using ag-ui-protocol ag-ui versions up to 2026-09-07 are affected. Upgrade to version 2026-09-08, which includes patch 30f8c794d5b73df5c610153043db502b2cc106cc.