A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder…
Medium CVSS 4.3
Summary
A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/a2ui-project/a2ui/
- https://github.com/a2ui-project/a2ui/issues/2296
- https://vuldb.com/cve/CVE-2026-92216
- https://vuldb.com/submit/934110
- https://vuldb.com/vuln/404461
- https://vuldb.com/vuln/404461/cti
Timeline
- nvd_ingest NVD