{"id":"CVE-2026-10032","published":"2026-08-04T16:16:20.983","lastModified":"2026-08-06T15:41:27.197","description":"The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq","tags":[]}],"exploitRefs":[{"url":"https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq","tags":[]}],"hasPoc":true,"ai":null}