Sceawere
Vulnerability Detail
CVE-2026-84887UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Agent-S Denial of Service Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- simular-ai
- Product
- Agent-S
- Attack Type
- Denial of Service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-03T05:16:47.333Z",
"pubdate": "2026-09-03T05:16:47.333Z",
"executiveSummary": "A denial of service (DoS) vulnerability has been identified in simular-ai Agent-S versions up to 0.3.2. The flaw resides within the Model-generated GUI Action Execution Workflow, specifically affecting the file grounding.py module.\nThis vulnerability allows a remote attacker to disrupt system availability by triggering a crash or resource exhaustion within the affected component. The issue stems from the way the application processes inputs during the GUI action execution lifecycle.\nGiven that public exploit material is available, the risk to deployments is elevated. The vendor has remained unresponsive to disclosure efforts, leaving current installations at risk of exploitation without a provided vendor-supplied patch.\nThe vulnerability is remotely exploitable, requiring no prior authentication or specific user interaction in many contexts. Successful exploitation results in the compromise of service stability, effectively preventing the Agent-S instance from performing automated tasks. Organizations utilizing Agent-S should treat this as a high-priority risk and implement compensatory controls immediately.",
"technicalDetails": "The vulnerability is localized to the file grounding.py component within the Model-generated GUI Action Execution Workflow of simular-ai Agent-S (up to version 0.3.2). The root cause involves improper validation or handling of data processed during the model-driven GUI interaction flow.\nIn the context of Agent-S, file grounding.py is responsible for mapping environmental data or model outputs to specific file-based GUI actions. When the system receives malicious or malformed input—often generated or intercepted during the model execution phase—the logic within this script fails to handle the input safely. This leads to an unhandled exception or an exhaustive loop that consumes system resources, resulting in a denial of service state for the agent process.\nThe attack flow commences with the remote actor delivering a specially crafted input that is intercepted or processed by the Agent-S workflow. Because the application interacts with external environments to execute GUI actions, the input vector can be triggered via network protocols leveraged by the agent. Upon receipt, the Model-generated GUI Action Execution Workflow parses this input and passes it to the vulnerable grounding.py function.\nDue to a lack of sufficient input sanitization or boundary checking, the processing function encounters an irrecoverable state. If the exploit triggers an unhandled exception in the execution thread, the Agent-S service terminates unexpectedly. Alternatively, if the exploit exploits the logic flow to cause infinite resource contention, the service becomes unresponsive, effectively halting all pending and future tasks.\nThe vulnerability is remotely exploitable, bypassing the need for local system access. As the Agent-S architecture is designed to handle autonomous workflows, it is inherently exposed to external inputs that govern its decision-making and action-execution capabilities. The availability of public exploit code allows actors with minimal technical sophistication to perform this attack, potentially impacting automated environments that rely on Agent-S for critical GUI-based workflows.\nPost-exploitation impact is primarily limited to service unavailability; however, if the service is configured to run with elevated system privileges, a crash may result in unintended residual state or the exposure of temporary files created during the failed action execution. Without a patch from the vendor, there is no inherent remediation within the application logic, and users must rely on external hardening."
}