CVE-2026-10032: @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default. ### Details The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`). **Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`: ```ts export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args => { if (args.url && typeof window !== 'undefined' && window.open) { window.open(args.url, '_blank'); } }); ``` `window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied. **Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`: ```ts export const OpenUrlApi = { name: 'openUrl' as const, returnType: 'void' as const, schema: z.object({ url: z.preprocess(v => (v === undefined ? undefined : String(v)), z.string()), }), }; ``` The Zod schema only requires a `string`; `javascript:` URIs pass validation without any rejection. **Full source-to-sink data flow:** 1. `renderers/web_core/src/v0_9/basic_catalog/components/basic_components.ts:356` — `ButtonApi` accepts `action: ActionSchema` (entry point). 2. `renderers/web_core/src/v0_9/schema/common-types.ts:126-130` — `ActionSchema` permits `{ functionCall: FunctionCallSchema }`. 3. `renderers/web_core/src/v0_9/rendering/generic-binder.ts:243-255` — on click, bound action calls `resolveDeepSync` then `dispatchAction`. 4. `renderers/web_core/src/v0_9/rendering/data-context.ts:93-105` — `resolveDynamicValue` detects the `call` key and invokes the named function. 5. `renderers/web_core/src/v0_9/catalog/types.ts:177-186` — catalog invoker runs `fn.schema.parse(rawArgs)` then `fn.execute()`. 6. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458` — `OpenUrlApi` validates `url` as `z.string()` only (no scheme check). 7. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430` — **sink**: `window.open(args.url, '_blank')` executes the `javascript:` URI. **All three renderers implemented in the A2UI repository are affected:** - React: `renderers/react/src/v0_9/catalog/basic/components/Button.tsx:33` — `onClick={props.action}` - Lit: `renderers/lit/src/v0_9/catalogs/basic/components/Button.ts:112` — `@click=${() => props.action()}` - Angular: `renderers/angular/src/v0_9/catalog/basic/button.component.ts:103-110` — `handleClick()` → `dataContext.resolveAction` → `dispatchAction` Any other A2UI renderer which depends on `web_core` and uses its basic catalog implementation is also affected. ### Remediation The issue was fixed in [https://github.com/a2ui-project/a2ui/pull/1707](https://github.com/a2ui-project/a2ui/pull/1707) and released in web\_core version 0.10.2, by blocking URLs that do not use the HTTP or HTTPS schemes, or those that are invalid. Please fix this issue in your project by depending on a @a2ui/web\_core version equal or greater than 0.10.2.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @a2ui/web_core 0.10.2.
Technical details
- Vendor
- Not specified
- Product
- @a2ui/web_core
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source