CVE-2026-92359: ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy

Published Sep 16, 2026
·
Updated

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function createstrandsapp of the file integrations/aws-strands/python/src/aguistrands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component.

Affected Software

1 affected component
ag-ui-protocol ag-ui=0.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy to a version that resolves this vulnerability.

    Fixed in AGUI.Abstractions@0.0.6Patch 9b143b9668fa52c2054ede9d34a45ac4b4401089

Event History

Sep 16, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What component and code path should teams review?

Review the CORSMiddleware configuration used by create_strands_app in integrations/aws-strands/python/src/ag_ui_strands/utils.py. The issue is associated with permissive cross-domain policy handling for untrusted domains.

2

What are the exploitation conditions?

The issue can be attacked remotely without privileges, but requires user interaction and high attack complexity. The available assessment describes exploitation as difficult and impact as limited to confidentiality.

3

What remediation is identified?

Upgrade to AGUI.Abstractions@0.0.6 or later. The identified fix is patch 9b143b9668fa52c2054ede9d34a45ac4b4401089.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203