Sceawere
Vulnerability Detail
CVE-2026-84885UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Agent-S Remote Denial Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- simular-ai
- Product
- Agent-S
- Attack Type
- Denial of Service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-03T05:16:47.010Z",
"pubdate": "2026-09-03T05:16:47.010Z",
"executiveSummary": "A remote denial-of-service (DoS) vulnerability has been identified in the CodeAgent component of simular-ai Agent-S, specifically affecting versions 0.3.1 and 0.3.2.\nThe vulnerability resides within an unspecified function in the code_agent.py file, allowing remote attackers to trigger a service disruption.\nThis flaw presents a significant risk to availability, as successful exploitation results in the inability of the agent to perform its intended functions.\nThe attack vector is remotely exploitable, requiring no prior authentication or elevated privileges, thus widening the potential threat landscape.\nGiven that the exploit is publicly disclosed and the vendor has remained unresponsive to disclosure attempts, systems running affected versions are currently at high risk of exploitation.\nOrganizations deploying Agent-S should treat this as a critical availability issue and implement necessary perimeter defenses to mitigate unauthorized interaction with the vulnerable component.",
"technicalDetails": "The vulnerability exists within the CodeAgent component of simular-ai Agent-S, specifically tied to processing logic housed in the code_agent.py file.\nThe root cause is an improper handling of input or state within an unidentified function in code_agent.py, which allows an attacker to induce a DoS condition.\nBecause the attack is launched remotely, the target is exposed via the network-facing interface of the Agent-S framework.\nThe attack flow entails an unauthenticated remote actor sending a specifically crafted payload or sequence of requests to the exposed service interface associated with the CodeAgent.\nUpon receipt of this malicious input, the affected function in code_agent.py enters a state that leads to service instability, process termination, or resource exhaustion, thereby effectively suspending the agent's operations.\nThe technical manifestation of the DoS is highly likely due to unvalidated inputs triggering an unhandled exception, infinite loop, or uncontrolled resource consumption (CPU/Memory) within the execution context of the CodeAgent.\nNo authentication or specific privilege level is required to initiate this attack, making it highly accessible to remote adversaries.\nSince the exploit code has been disclosed to the public, the barrier to entry for potential attackers is minimal, requiring only the ability to reach the service over the network.\nThe post-exploitation impact is immediate unavailability of the agent's services. In an automation context where Agent-S is integrated into development or operational pipelines, this disruption can halt critical workflows that rely on the agent's code execution or analytical capabilities.\nThe lack of vendor response means that automated patch management is currently unavailable, leaving the burden of remediation entirely on the administrator of the affected systems to apply manual workarounds or network-level blocking."
}