{"id":"CVE-2026-10032","title":"The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme","summary":"The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall ac…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"google","product":"a2ui/web_core","affected":["a2ui/web_core >= 0.9.0, < 0.10.2"],"patched":["a2ui/web_core 0.10.2"],"published":"2026-08-04","updated":"2026-09-23","sourceUpdated":"2026-09-23T15:59:07.417","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-10032","references":[{"url":"https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq","label":"cve-coordination@google.com"}],"tags":["nvd"],"epss":0.00197,"epssPercentile":0.0968,"ingestedAt":"2026-09-23T16:27:22.625Z","slug":"CVE-2026-10032","body":"## Overview\n\nThe openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.\n\n## Affected\n\n- `a2ui/web_core >= 0.9.0, < 0.10.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `a2ui/web_core 0.10.2`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}