← Back to CVE List
CVE-2026-10032NVD
Vulnerability Summary
### Summary
The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default.
### Details
The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`).
**Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`:
```ts
export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args => {
if (args.url && typeof window !== 'undefined' && window.open) {
window.open(args.url, '_blank');
}
});
```
`window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied.
**Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`:
```ts
export const OpenUrlApi = {
name: 'openUrl' as const,
returnType: 'void' as const,
schema: z.object({
url: z.preprocess(v => (v === undefined ? undefined : String(v)), z.string()),
}),
};
```
The Zod schema only requires a `string`; `javascript:` URIs pass validation without any rejection.
**Full source-to-sink data flow:**
1. `renderers/web_core/src/v0_9/basic_catalog/components/basic_components.ts:356` — `ButtonApi` accepts `action: ActionSchema` (entry point).
2. `renderers/web_core/src/v0_9/schema/common-types.ts:126-130` — `ActionSchema` permits `{ functionCall: FunctionCallSchema }`.
3. `renderers/web_core/src/v0_9/rendering/generic-binder.ts:243-255` — on click, bound action calls `resolveDeepSync` then `dispatchAction`.
4. `renderers/web_core/src/v0_9/rendering/data-context.ts:93-105` — `resolveDynamicValue` detects the `call` key and invokes the named function.
5. `renderers/web_core/src/v0_9/catalog/types.ts:177-186` — catalog invoker runs `fn.schema.parse(rawArgs)` then `fn.execute()`.
6. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458` — `OpenUrlApi` validates `url` as `z.string()` only (no scheme check).
7. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430` — **sink**: `window.open(args.url, '_blank')` executes the `javascript:` URI.
**All three renderers implemented in the A2UI repository are affected:**
- React: `renderers/react/src/v0_9/catalog/basic/components/Button.tsx:33` — `onClick={props.action}`
- Lit: `renderers/lit/src/v0_9/catalogs/basic/components/Button.ts:112` — `@click=${() => props.action()}`
- Angular: `renderers/angular/src/v0_9/catalog/basic/button.component.ts:103-110` — `handleClick()` → `dataContext.resolveAction` → `dispatchAction`
Any other A2UI renderer which depends on `web_core` and uses its basic catalog implementation is also affected.
### Remediation
The issue was fixed in [https://github.com/a2ui-project/a2ui/pull/1707](https://github.com/a2ui-project/a2ui/pull/1707) and released in web\_core version 0.10.2, by blocking URLs that do not use the HTTP or HTTPS schemes, or those that are invalid.
Please fix this issue in your project by depending on a @a2ui/web\_core version equal or greater than 0.10.2.
The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default.
### Details
The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`).
**Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`:
```ts
export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args => {
if (args.url && typeof window !== 'undefined' && window.open) {
window.open(args.url, '_blank');
}
});
```
`window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied.
**Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`:
```ts
export const OpenUrlApi = {
name: 'openUrl' as const,
returnType: 'void' as const,
schema: z.object({
url: z.preprocess(v => (v === undefined ? undefined : String(v)), z.string()),
}),
};
```
The Zod schema only requires a `string`; `javascript:` URIs pass validation without any rejection.
**Full source-to-sink data flow:**
1. `renderers/web_core/src/v0_9/basic_catalog/components/basic_components.ts:356` — `ButtonApi` accepts `action: ActionSchema` (entry point).
2. `renderers/web_core/src/v0_9/schema/common-types.ts:126-130` — `ActionSchema` permits `{ functionCall: FunctionCallSchema }`.
3. `renderers/web_core/src/v0_9/rendering/generic-binder.ts:243-255` — on click, bound action calls `resolveDeepSync` then `dispatchAction`.
4. `renderers/web_core/src/v0_9/rendering/data-context.ts:93-105` — `resolveDynamicValue` detects the `call` key and invokes the named function.
5. `renderers/web_core/src/v0_9/catalog/types.ts:177-186` — catalog invoker runs `fn.schema.parse(rawArgs)` then `fn.execute()`.
6. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458` — `OpenUrlApi` validates `url` as `z.string()` only (no scheme check).
7. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430` — **sink**: `window.open(args.url, '_blank')` executes the `javascript:` URI.
**All three renderers implemented in the A2UI repository are affected:**
- React: `renderers/react/src/v0_9/catalog/basic/components/Button.tsx:33` — `onClick={props.action}`
- Lit: `renderers/lit/src/v0_9/catalogs/basic/components/Button.ts:112` — `@click=${() => props.action()}`
- Angular: `renderers/angular/src/v0_9/catalog/basic/button.component.ts:103-110` — `handleClick()` → `dataContext.resolveAction` → `dispatchAction`
Any other A2UI renderer which depends on `web_core` and uses its basic catalog implementation is also affected.
### Remediation
The issue was fixed in [https://github.com/a2ui-project/a2ui/pull/1707](https://github.com/a2ui-project/a2ui/pull/1707) and released in web\_core version 0.10.2, by blocking URLs that do not use the HTTP or HTTPS schemes, or those that are invalid.
Please fix this issue in your project by depending on a @a2ui/web\_core version equal or greater than 0.10.2.
CVSS v3.1 Base Metrics — Score 9.3
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- @a2ui/web_core >= 0.9.0, < 0.10.2
Not provided by Private for this CVE.
External References
- https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq
- https://nvd.nist.gov/vuln/detail/CVE-2026-10032
- https://github.com/a2ui-project/a2ui/pull/1707
- https://github.com/a2ui-project/a2ui/commit/71573078c4168b2dc166bb847c3a85715dadc675
- https://github.com/advisories/GHSA-72qq-p3r5-f7wq