Multiple vulnerabilities in simular-ai Agent-S
Three vulnerabilities were identified in simular-ai Agent-S up to version 0.3.2, affecting the OCR HTTP API, CodeAgent, and Model-generated GUI Action Execution Workflow components. All vulnerabilities enable remote denial of service or resource consumption attacks, with publicly disclosed exploits available.
Disclosed 3 September 2026 · Record updated 13 September 2026
Impact
Remote attackers can trigger resource consumption and denial of service attacks through manipulation of OCR HTTP API arguments, CodeAgent functionality, and GUI Action Execution Workflow.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-wvcq-2rcq-fqc9
- github.comhttps://github.com/advisories/GHSA-5wcc-3m77-2xf5
- github.comhttps://github.com/advisories/GHSA-3j2w-rmqf-7fcr
