PT-2026-84883 · Simular Ai · Ms-Agent
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
simular-ai Agent-S versions prior to 0.3.3
Description
A remote resource consumption issue exists within the OCR HTTP API component. The problem resides in the
ImageData() function located in the gui agents/s1/utils/ocr server.py file. A remote attacker can trigger this by manipulating the img bytes argument.Recommendations
Update simular-ai Agent-S to a version newer than 0.3.2.
As a temporary mitigation, restrict access to the
ImageData() function within the OCR HTTP API to minimize the risk of exploitation.Exploit
Fix
Resource Exhaustion
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ms-Agent