<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:a2ui:web_core:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aa2uiweb_core/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:50:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aa2uiweb_core/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Site Scripting in @a2ui/web_core via openUrl</title><link>https://feed.craftedsignal.io/briefs/2026-10-a2ui-xss/</link><pubDate>Sat, 03 Oct 2026 04:50:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-a2ui-xss/</guid><description>The @a2ui/web_core package (CVE-2026-10032) contains a critical cross-site scripting (XSS) vulnerability in the openUrl function, allowing arbitrary JavaScript execution via agent-supplied javascript: URIs.</description><content:encoded><![CDATA[<p>The <code>@a2ui/web_core</code> package is vulnerable to a stored or reflected cross-site scripting (XSS) attack (CVE-2026-10032) due to improper input validation in the <code>openUrl</code> function. An attacker-controlled agent can provide a <code>javascript:</code> URI as the <code>url</code> argument to a <code>Button</code> component's <code>functionCall</code> action. When a victim interacts with the button, the underlying <code>openUrl</code> implementation invokes <code>window.open()</code> with the unsanitized input, executing the JavaScript payload within the victim application's browser origin. This affects all renderers (React, Lit, and Angular) that utilize the Basic Catalog implementation provided by <code>web_core</code>. This vulnerability was identified in all versions from 0.9.0 up to, but not including, 0.10.2.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker designs a malicious agent response containing a <code>Button</code> component with a <code>functionCall</code> action.</li>
<li>The action is configured to trigger the <code>openUrl</code> function with a <code>url</code> parameter set to a <code>javascript:</code> URI (e.g., <code>javascript:alert(document.cookie)</code>).</li>
<li>The A2UI runtime library, specifically <code>generic-binder.ts</code>, intercepts the component click event.</li>
<li>The library calls <code>dispatchAction</code>, which triggers <code>resolveDynamicValue</code> to identify the function call.</li>
<li>The <code>OpenUrlApi</code> schema parser validates the input using only a basic string check, allowing the malicious URI to pass.</li>
<li>The <code>OpenUrlImplementation</code> passes the unvalidated URL string directly into <code>window.open()</code>.</li>
<li>The browser executes the injected JavaScript code in the context of the user session, leading to full XSS.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the execution of arbitrary JavaScript in the victim's browser. This can lead to session hijacking, unauthorized actions performed on behalf of the user, theft of sensitive data, or redirection to malicious websites. As this vulnerability resides in a core UI component library used across multiple frameworks, any application integrating <code>@a2ui/web_core</code> versions prior to 0.10.2 is susceptible to attack.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and engineering teams to mitigate CVE-2026-10032:</p>
<ul>
<li>Update the dependency <code>@a2ui/web_core</code> to version 0.10.2 or later in all projects, as this release implements strict URI scheme validation to block non-HTTP/HTTPS protocols.</li>
<li>Audit applications utilizing <code>@a2ui/web_core</code> to identify where agent-supplied inputs are mapped to button actions or URI-handling functions.</li>
<li>Implement Content Security Policy (CSP) headers that restrict script sources and prevent inline script execution to mitigate the impact of potential XSS vulnerabilities in the front-end layer.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>injection</category></item></channel></rss>