CRITICAL 9.3 GitHub
CVE-2026-10032
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
### Summary
The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by def
Affected Products
- npm/@a2ui/web_core >= 0.9.0, < 0.10.2
References
- https://github.com/advisories/GHSA-72qq-p3r5-f7wq
- https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq
- https://nvd.nist.gov/vuln/detail/CVE-2026-10032
- https://github.com/a2ui-project/a2ui/pull/1707
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-02 via GitHub. Affected: npm/@a2ui/web_core >= 0.9.0, < 0.10.2.
Risk Timeline
CVE Disclosed2026-10-02 · 0 days ago
Remediation Resources
NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2026-10032Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-92940 | vm2 exposes host HTTPS credentials and TLS traffic through globalAgent | CRITICAL | 10.0 |
| CVE-2026-92937 | vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection | CRITICAL | 10.0 |
| CVE-2026-92941 | vm2 NodeVM can replace the host process TLS trust store | CRITICAL | 10.0 |
| CVE-2026-92948 | vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox | CRITICAL | 9.9 |
| CVE-2026-92951 | vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading | CRITICAL | 9.9 |
| CVE-2026-92957 | vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process | CRITICAL | 9.9 |
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.