Junglewise Threat Intelligence

CVE-2026-85100: 2FastLabs agent-squad resource exhaustion in streaming agent workflow

CVE-2026-85100 · Severity: medium · CVSS 4.3 · Published 2026-09-03

Executive brief

Agent Squad is a framework for managing multiple AI agents in conversational applications. A vulnerability in its streaming agent response workflow allows attackers to exhaust server resources remotely, potentially causing service denial or performance degradation without requiring authentication.

Technical details

The vulnerability exists in the AgentSquad.routeRequest function within the Streaming Agent Response Workflow component (agent-squad/typescript/src/orchestrator.ts). The flaw results in uncontrolled resource consumption, allowing remote attackers to trigger excessive resource usage. No authentication is required to exploit this issue. The attack vector is network-based and can be executed by unauthenticated users. A patch or fix availability has not been confirmed, as the project maintainers had not responded to early issue notification at the time of reporting.

Affected products

  • 2FastLabs agent-squad up to 1.1.4

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: advisory: CVE-2026-85100 published; exploit is public

References