2Fastlabs · Agent-Squad · CVE-2026-85100
**Name of the Vulnerable Software and Affected Versions**
2FastLabs agent-squad versions prior to 1.1.5
**Description**
A remote issue exists within the Streaming Agent Response Workflow component, specifically in the `AgentSquad.routeRequest()` function located in the `agent-squad/typescript/src/orchestrator.ts` file. Manipulation of this function can lead to excessive resource consumption.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the `AgentSquad.routeRequest()` function to minimize the risk of exploitation.