<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:54:11.662600+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344199</id>
    <title>EUVD-2026-344199</title>
    <updated>2026-10-05T18:54:11.730740+00:00</updated>
    <content>EUVD-2026-344199</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10032</id>
    <title>fkie_cve-2026-10032</title>
    <updated>2026-10-05T18:54:11.730777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-10032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-72qq-p3r5-f7wq</id>
    <title>GHSA-72qq-p3r5-f7wq — @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions</title>
    <updated>2026-10-05T18:54:11.730813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @a2ui/web_core</p>
<p>### Summary</p>
<p>The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default.</p>
<p>### Details</p>
<p>The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`).</p>
<p>**Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`:</p>
<p>```ts
export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args =&gt; {
  if (args.url &amp;&amp; typeof window !== 'undefined' &amp;&amp; window.open) {
    window.open(args.url, '_blank');
  }
});
```</p>
<p>`window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied.</p>
<p>**Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`:</p>
<p>```ts
export const OpenUrlApi = {
  name: 'openUrl' as const,
  returnType: 'void' as const,
  schema: z.object({
    url: z.preprocess(v =&gt; (v === undefined ? undefined : String(v)), z.string()),
  }),
};
```</p>
<p>The Zod schema only requires a `string`; `javas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-72qq-p3r5-f7wq"/>
  </entry>
</feed>
