← العودة للجدول
CVE-2026-10032
CVE-2026-10032 — @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied
📅 2026-10-03
🔴 Critical 🔥 No GHSA Vulnerability Web CVSS 9.3

📋 الوصف الكامل

### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, cons

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-10032

📡 المصدر

GHSA

✅ الحلول والتخفيف

Update to v0.10.2

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←