---
id: CVE-2026-92214
title: A flaw has been found in a2ui-project a2ui up to 0.10.7
summary: >-
  A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an
  unknown function of the file
  samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts
  of the component a2a-c…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: a2ui-project
product: a2ui
affected:
  - a2ui 0.10.0
  - a2ui 0.10.1
  - a2ui 0.10.2
  - a2ui 0.10.3
  - a2ui 0.10.4
  - a2ui 0.10.5
  - a2ui 0.10.6
  - a2ui 0.10.7
published: '2026-09-16'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T16:18:10.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92214'
references:
  - url: 'https://github.com/a2ui-project/a2ui/'
    label: cna@vuldb.com
  - url: 'https://github.com/a2ui-project/a2ui/issues/2294'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92214'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/934108'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/404459'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/404459/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00348
epssPercentile: 0.25711
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T15:10:21.600356Z'
ingestedAt: '2026-09-16T01:47:46.208Z'
---

## Overview

A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
