CVE-2026-85100CWE-400CWE-404denial-of-service

CVE-2026-85100

Medium · published September 3, 2026

CVSS v3.1
4.3
EPSS
1%
Percentile
42.4
In the wild
Unconfirmed
What it is

A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component Streaming Agent Response Workflow. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00522 · 42.4th percentile
Weaknesses
CWE-400 · Uncontrolled Resource Consumption; CWE-404 · Improper Resource Shutdown or Release
Published
2026-09-03T17:06Z
References (9)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 1%
    epss
  • 03 SEP 09:45Z
    2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeRequest resource consumption
    cvelistv5