{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agooglea2ui%5C/web_corenode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:a2ui:web_core:*:*:*:*:*:*:*:*","cpe:2.3:a:google:a2ui\\/web_core:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2026-10032"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@a2ui/web_core (\u003e= 0.9.0, \u003c 0.10.2)"],"_cs_severities":["low"],"_cs_tags":["web-vulnerability","xss","injection"],"_cs_type":"advisory","_cs_vendors":["a2ui"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@a2ui/web_core\u003c/code\u003e package is vulnerable to a stored or reflected cross-site scripting (XSS) attack (CVE-2026-10032) due to improper input validation in the \u003ccode\u003eopenUrl\u003c/code\u003e function. An attacker-controlled agent can provide a \u003ccode\u003ejavascript:\u003c/code\u003e URI as the \u003ccode\u003eurl\u003c/code\u003e argument to a \u003ccode\u003eButton\u003c/code\u003e component's \u003ccode\u003efunctionCall\u003c/code\u003e action. When a victim interacts with the button, the underlying \u003ccode\u003eopenUrl\u003c/code\u003e implementation invokes \u003ccode\u003ewindow.open()\u003c/code\u003e with the unsanitized input, executing the JavaScript payload within the victim application's browser origin. This affects all renderers (React, Lit, and Angular) that utilize the Basic Catalog implementation provided by \u003ccode\u003eweb_core\u003c/code\u003e. This vulnerability was identified in all versions from 0.9.0 up to, but not including, 0.10.2.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker designs a malicious agent response containing a \u003ccode\u003eButton\u003c/code\u003e component with a \u003ccode\u003efunctionCall\u003c/code\u003e action.\u003c/li\u003e\n\u003cli\u003eThe action is configured to trigger the \u003ccode\u003eopenUrl\u003c/code\u003e function with a \u003ccode\u003eurl\u003c/code\u003e parameter set to a \u003ccode\u003ejavascript:\u003c/code\u003e URI (e.g., \u003ccode\u003ejavascript:alert(document.cookie)\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe A2UI runtime library, specifically \u003ccode\u003egeneric-binder.ts\u003c/code\u003e, intercepts the component click event.\u003c/li\u003e\n\u003cli\u003eThe library calls \u003ccode\u003edispatchAction\u003c/code\u003e, which triggers \u003ccode\u003eresolveDynamicValue\u003c/code\u003e to identify the function call.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eOpenUrlApi\u003c/code\u003e schema parser validates the input using only a basic string check, allowing the malicious URI to pass.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eOpenUrlImplementation\u003c/code\u003e passes the unvalidated URL string directly into \u003ccode\u003ewindow.open()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe browser executes the injected JavaScript code in the context of the user session, leading to full XSS.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript in the victim's browser. This can lead to session hijacking, unauthorized actions performed on behalf of the user, theft of sensitive data, or redirection to malicious websites. As this vulnerability resides in a core UI component library used across multiple frameworks, any application integrating \u003ccode\u003e@a2ui/web_core\u003c/code\u003e versions prior to 0.10.2 is susceptible to attack.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and engineering teams to mitigate CVE-2026-10032:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the dependency \u003ccode\u003e@a2ui/web_core\u003c/code\u003e to version 0.10.2 or later in all projects, as this release implements strict URI scheme validation to block non-HTTP/HTTPS protocols.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing \u003ccode\u003e@a2ui/web_core\u003c/code\u003e to identify where agent-supplied inputs are mapped to button actions or URI-handling functions.\u003c/li\u003e\n\u003cli\u003eImplement Content Security Policy (CSP) headers that restrict script sources and prevent inline script execution to mitigate the impact of potential XSS vulnerabilities in the front-end layer.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T04:50:17Z","date_published":"2026-10-03T04:50:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-a2ui-xss/","summary":"The @a2ui/web_core package (CVE-2026-10032) contains a critical cross-site scripting (XSS) vulnerability in the openUrl function, allowing arbitrary JavaScript execution via agent-supplied javascript: URIs.","title":"Cross-Site Scripting in @a2ui/web_core via openUrl","url":"https://feed.craftedsignal.io/briefs/2026-10-a2ui-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:google:a2ui\\/Web_core:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}