Disclosure summary
### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default. ### Details The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`). **Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`: ```ts export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args => { if (args.url && typeof window !== 'undefined' && window.open) { window.open(args.url, '_blank'); } }); ``` `window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied. **Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_fu
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-72qq-p3r5-f7wq
Open original source · Updated Oct 02, 2026
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @a2ui/web_core | >= 0.9.0, < 0.10.2 | 0.10.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-02T18:55:49-04:00
MODIFIED 2026-10-02T18:55:50-04:00
INGESTED 2026-10-06T11:45:17-04:00