---
id: CVE-2026-92216
title: A vulnerability was found in a2ui-project a2ui up to 0.10.7
summary: >-
  A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this
  issue is the function openUrl of the file
  renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component
  Binder. The manipulation results in open red…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-601
vendor: a2ui-project
product: a2ui
affected:
  - a2ui 0.10.0
  - a2ui 0.10.1
  - a2ui 0.10.2
  - a2ui 0.10.3
  - a2ui 0.10.4
  - a2ui 0.10.5
  - a2ui 0.10.6
  - a2ui 0.10.7
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:18:05.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92216'
references:
  - url: 'https://github.com/a2ui-project/a2ui/'
    label: cna@vuldb.com
  - url: 'https://github.com/a2ui-project/a2ui/issues/2296'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92216'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/934110'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/404461'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/404461/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T18:53:34.473173Z'
ingestedAt: '2026-09-16T02:48:25.628Z'
epss: 0.00485
epssPercentile: 0.39079
---

## Overview

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
