CVE-2026-84887CWE-404

CVE-2026-84887

Medium · published September 3, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
26.0
In the wild
Unconfirmed
What it is

A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00332 · 26.0th percentile
Weakness
CWE-404 · Improper Resource Shutdown or Release
Published
2026-09-03T09:16Z
References (5)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 21:00Z
    simular-ai Agent-S Model-generated GUI Action Execution Workflow grounding.py denial of service
    cvelistv5