PatchSiren

simular-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW simular-ai CVE published 2026-09-03

CVE-2026-84887

A vulnerability was identified in simular-ai Agent-S up to 0.3.2, affecting the Model-generated GUI Action Execution Workflow, specifically in the grounding.py file. This issue could lead to denial of service and remote exploitation is possible. The CVSS score is 2.1 (Low). Security teams should focus on verifying affected versions, implementing compensating controls, and monitoring for exploitation attem [truncated]

MEDIUM simular-ai CVE published 2026-09-03

CVE-2026-84886

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-03T05:16:47.167Z and has not been modified since then. The vulnerability affects simular-ai Agent-S up to version 0.3.2, specifically in the ImageData function of the gui_agents/s1/utils/ocr_server.py file. This function is part of the OCR HTTP API and can lead to resource consumption through manipu [truncated]

LOW simular-ai CVE published 2026-09-03

CVE-2026-84885

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-03T05:16:47.010Z and has not been modified since then. This vulnerability affects simular-ai Agent-S versions 0.3.1 and 0.3.2, specifically in the code_agent.py file of the CodeAgent component, leading to a denial of service. The attack can be launched remotely. Users should review their inventory a [truncated]