VYPR

A2ui

by A2ui Project

Source repositories

CVEs (2)

  • CVE-2026-10032MedAug 4, 2026
    risk 0.40cvss epss 0.00

    The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered…

  • CVE-2026-92114MedSep 15, 2026
    risk 0.27cvss 5.3epss

    A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipulation leads to inefficient regular expression complexity.…