OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-10032: @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions

GitHub Advisories · officialPublished Oct 2, 2026Risk 50/100

### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default. ### Details The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`). **Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`: ```ts export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args => { if (args.url && typeof window !== 'undefined' && window.open) { window.open(args.url, '_blank'); } }); ``` `window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied. **Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`: ```ts export const OpenUrlApi = { name: 'openUrl' as const, returnType: 'void' as const, schema: z.object({ url: z.preprocess(v => (v === undefined ? undefined : String(v)), z.string()), }), }; ``` The Zod schema only requires a `string`; `javascript:` URIs pass validation without any rejection. **Full source-to-sink data flow:** 1. `renderers/web_core/src/v0_9/basic_catalog/components/basic_components.ts:356` — `ButtonApi` accepts `action: ActionSchema` (entry point). 2. `renderers/web_core/src/v0_9/schema/common-types.ts:126-130` — `ActionSchema` permits `{ functionCall: FunctionCallSchema }`. 3. `renderers/web_core/src/v0_9/rendering/generic-binder.ts:243-255` — on click, bound action calls `resolveDeepSync` then `dispatchAction`. 4. `renderers/web_core/src/v0_9/rendering/data-context.ts:93-105` — `resolveDynamicValue` detects the `call` key and invokes the named function. 5. `renderers/web_core/src/v0_9/catalog/types.ts:177-186` — catalog invoker runs `fn.schema.parse(rawArgs)` then `fn.execute()`. 6. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458` — `OpenUrlApi` validates `url` as `z.string()` only (no scheme check). 7. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430` — **sink**: `window.open(args.url, '_blank')` executes the `javascript:` URI. **All three renderers implemented in the A2UI repository are affected:** - React: `renderers/react/src/v0_9/catalog/basic/components/Button.tsx:33` — `onClick={props.action}` - Lit: `renderers/lit/src/v0_9/catalogs/basic/components/Button.ts:112` — `@click=${() => props.action()}` - Angular: `renderers/angular/src/v0_9/catalog/basic/button.component.ts:103-110` — `handleClick()` → `dataContext.resolveAction` → `dispatchAction` Any other A2UI renderer which depends on `web_core` and uses its basic catalog implementation is also affected. ### Remediation The issue was fixed in [https://github.com/a2ui-project/a2ui/pull/1707](https://github.com/a2ui-project/a2ui/pull/1707) and released in web\_core version 0.10.2, by blocking URLs that do not use the HTTP or HTTPS schemes, or those that are invalid. Please fix this issue in your project by depending on a @a2ui/web\_core version equal or greater than 0.10.2.

Upgrade affected packages to a patched version: @a2ui/web_core 0.10.2.

Vendor
Not specified
Product
@a2ui/web_core
Exploitation
none known
Evidence
official
CVSS
9.3

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source