Cross-Site Scripting in @a2ui/web_core via openUrl
The @a2ui/web_core package (CVE-2026-10032) contains a critical cross-site scripting (XSS) vulnerability in the openUrl function, allowing arbitrary JavaScript execution via agent-supplied javascript: URIs.
CVE search metadata
CVE search record: CVE-2026-10032. Severity: medium. CVSS: 6.1. EPSS: 0.13%. KEV: no. Product: @a2ui/web_core (>= 0.9.0, < 0.10.2). Brief: Cross-Site Scripting in @a2ui/web_core via openUrl. Brief link: https://feed.craftedsignal.io/briefs/2026-10-a2ui-xss/
The @a2ui/web_core package is vulnerable to a stored or reflected cross-site scripting (XSS) attack (CVE-2026-10032) due to improper input validation in the openUrl function. An attacker-controlled agent can provide a javascript: URI as the url argument to a Button component's functionCall action. When a victim interacts with the button, the underlying openUrl implementation invokes window.open() with the unsanitized input, executing the JavaScript payload within the victim application's browser origin. This affects all renderers (React, Lit, and Angular) that utilize the Basic Catalog implementation provided by web_core. This vulnerability was identified in all versions from 0.9.0 up to, but not including, 0.10.2.
Attack Chain
- An attacker designs a malicious agent response containing a
Buttoncomponent with afunctionCallaction. - The action is configured to trigger the
openUrlfunction with aurlparameter set to ajavascript:URI (e.g.,javascript:alert(document.cookie)). - The A2UI runtime library, specifically
generic-binder.ts, intercepts the component click event. - The library calls
dispatchAction, which triggersresolveDynamicValueto identify the function call. - The
OpenUrlApischema parser validates the input using only a basic string check, allowing the malicious URI to pass. - The
OpenUrlImplementationpasses the unvalidated URL string directly intowindow.open(). - The browser executes the injected JavaScript code in the context of the user session, leading to full XSS.
Impact
Successful exploitation allows for the execution of arbitrary JavaScript in the victim's browser. This can lead to session hijacking, unauthorized actions performed on behalf of the user, theft of sensitive data, or redirection to malicious websites. As this vulnerability resides in a core UI component library used across multiple frameworks, any application integrating @a2ui/web_core versions prior to 0.10.2 is susceptible to attack.
Recommendation
Prioritized actions for security and engineering teams to mitigate CVE-2026-10032:
- Update the dependency
@a2ui/web_coreto version 0.10.2 or later in all projects, as this release implements strict URI scheme validation to block non-HTTP/HTTPS protocols. - Audit applications utilizing
@a2ui/web_coreto identify where agent-supplied inputs are mapped to button actions or URI-handling functions. - Implement Content Security Policy (CSP) headers that restrict script sources and prevent inline script execution to mitigate the impact of potential XSS vulnerabilities in the front-end layer.
Immediate actions
Upgrade @a2ui/web_core to 0.10.2 or later
Mitigations
Upgrade vulnerable dependencies
CVE-2026-10032