Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-8319: Remote resource exhaustion in aiwaves-cn agents memory recall function

A vulnerability in the aiwaves-cn 'agents' project (cheshire_cat_core component) allows remote attackers to trigger excessive resource consumption via the recall_relevant_memories_to_working_memory function in core/cat/looking_glass/stray_cat.py. A public exploit exists and the maintainers have not responded to the issue report.

Disclosed 11 May 2026 · Record updated 13 September 2026

Impact

Remotely exploitable resource consumption (denial-of-service style) condition with a publicly available exploit; no fix released as the project has not responded.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-8319