{"id":"GHSA-72qq-p3r5-f7wq","summary":"@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions","details":"### Summary\n\nThe `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default.\n\n### Details\n\nThe vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`).\n\n**Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`:\n\n```ts\nexport const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args =\u003e {\n  if (args.url && typeof window !== 'undefined' && window.open) {\n    window.open(args.url, '_blank');\n  }\n});\n```\n\n`window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied.\n\n**Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`:\n\n```ts\nexport const OpenUrlApi = {\n  name: 'openUrl' as const,\n  returnType: 'void' as const,\n  schema: z.object({\n    url: z.preprocess(v =\u003e (v === undefined ? undefined : String(v)), z.string()),\n  }),\n};\n```\n\nThe Zod schema only requires a `string`; `javascript:` URIs pass validation without any rejection.\n\n**Full source-to-sink data flow:**\n\n1. `renderers/web_core/src/v0_9/basic_catalog/components/basic_components.ts:356` — `ButtonApi` accepts `action: ActionSchema` (entry point).  \n2. `renderers/web_core/src/v0_9/schema/common-types.ts:126-130` — `ActionSchema` permits `{ functionCall: FunctionCallSchema }`.  \n3. `renderers/web_core/src/v0_9/rendering/generic-binder.ts:243-255` — on click, bound action calls `resolveDeepSync` then `dispatchAction`.  \n4. `renderers/web_core/src/v0_9/rendering/data-context.ts:93-105` — `resolveDynamicValue` detects the `call` key and invokes the named function.  \n5. `renderers/web_core/src/v0_9/catalog/types.ts:177-186` — catalog invoker runs `fn.schema.parse(rawArgs)` then `fn.execute()`.  \n6. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458` — `OpenUrlApi` validates `url` as `z.string()` only (no scheme check).  \n7. `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430` — **sink**: `window.open(args.url, '_blank')` executes the `javascript:` URI.\n\n**All three renderers implemented in the A2UI repository are affected:**\n\n- React: `renderers/react/src/v0_9/catalog/basic/components/Button.tsx:33` — `onClick={props.action}`  \n- Lit: `renderers/lit/src/v0_9/catalogs/basic/components/Button.ts:112` — `@click=${() =\u003e props.action()}`  \n- Angular: `renderers/angular/src/v0_9/catalog/basic/button.component.ts:103-110` — `handleClick()` → `dataContext.resolveAction` → `dispatchAction`\n\nAny other A2UI renderer which depends on `web_core` and uses its basic catalog implementation is also affected.\n\n### Remediation\n\nThe issue was fixed in [https://github.com/a2ui-project/a2ui/pull/1707](https://github.com/a2ui-project/a2ui/pull/1707) and released in web\\_core version 0.10.2, by blocking URLs that do not use the HTTP or HTTPS schemes, or those that are invalid.\n\nPlease fix this issue in your project by depending on a @a2ui/web\\_core version equal or greater than 0.10.2.","aliases":["CVE-2026-10032"],"modified":"2026-10-02T23:15:05.516445221Z","published":"2026-10-02T22:55:49Z","database_specific":{"github_reviewed_at":"2026-10-02T22:55:49Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/a2ui-project/a2ui/security/advisories/GHSA-72qq-p3r5-f7wq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10032"},{"type":"WEB","url":"https://github.com/a2ui-project/a2ui/pull/1707"},{"type":"WEB","url":"https://github.com/a2ui-project/a2ui/commit/71573078c4168b2dc166bb847c3a85715dadc675"},{"type":"PACKAGE","url":"https://github.com/a2ui-project/a2ui"}],"affected":[{"package":{"name":"@a2ui/web_core","ecosystem":"npm","purl":"pkg:npm/%40a2ui/web_core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.9.0"},{"fixed":"0.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-72qq-p3r5-f7wq/GHSA-72qq-p3r5-f7wq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"}]}