VYPR
Vendor

A2ui Project

Products
1
CVEs
9
Across products
9
Status
Private

Products

1

Recent CVEs

9
  • CVE-2026-92217MedSep 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determined object…

  • CVE-2026-92215HigSep 16, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileResolver. The manipulation leads to…

  • CVE-2026-10032MedAug 4, 2026
    risk 0.40cvss epss 0.00

    The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered…

  • CVE-2026-92213MedSep 16, 2026
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argument primaryColor results in injection. The…

  • CVE-2026-92356MedSep 16, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The…

  • CVE-2026-92216MedSep 16, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack…

  • CVE-2026-92114MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.01

    A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipulation leads to inefficient regular expression complexity.…

  • CVE-2026-92214LowSep 16, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing a manipulation can…

  • CVE-2026-92357MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disclosure. The attack may be initiated…