CRITICAL 9.3 GitHub

CVE-2026-10032

@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions

### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by def

Affected Products

References

Published: 2026-10-02 · Source: GitHub · Feed updated: 2026-10-03
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-02 via GitHub. Affected: npm/@a2ui/web_core >= 0.9.0, < 0.10.2.

Risk Timeline

CVE Disclosed2026-10-02 · 0 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-92940vm2 exposes host HTTPS credentials and TLS traffic through globalAgentCRITICAL10.0
CVE-2026-92937vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirectionCRITICAL10.0
CVE-2026-92941vm2 NodeVM can replace the host process TLS trust storeCRITICAL10.0
CVE-2026-92948vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandboxCRITICAL9.9
CVE-2026-92951vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading CRITICAL9.9
CVE-2026-92957vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_processCRITICAL9.9
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.