CVE-2026-92359: ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy
A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function createstrandsapp of the file integrations/aws-strands/python/src/aguistrands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policyto a version that resolves this vulnerability.Fixed in AGUI.Abstractions@0.0.6Patch 9b143b9668fa52c2054ede9d34a45ac4b4401089
Event History
Frequently Asked Questions
What component and code path should teams review?
Review the CORSMiddleware configuration used by create_strands_app in integrations/aws-strands/python/src/ag_ui_strands/utils.py. The issue is associated with permissive cross-domain policy handling for untrusted domains.
What are the exploitation conditions?
The issue can be attacked remotely without privileges, but requires user interaction and high attack complexity. The available assessment describes exploitation as difficult and impact as limited to confidentiality.
What remediation is identified?
Upgrade to AGUI.Abstractions@0.0.6 or later. The identified fix is patch 9b143b9668fa52c2054ede9d34a45ac4b4401089.