CVE-2026-92359 | ag-ui-protocol ag-ui 0.3.0 CORSMiddleware utils.py create_strands_app cross-domain policy (Issue 2433)

SecurityVulns

A vulnerability was found in ag-ui-protocol ag-ui 0.3.0 and classified as problematic. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is cataloged as CVE-2026-92359. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More