<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:52:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-344199</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344199</link>
      <description>EUVD-2026-344199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344199</guid>
    </item>
    <item>
      <title>fkie_cve-2026-10032</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10032</link>
      <description>&lt;p&gt;The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component&amp;#39;s functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application&amp;#39;s browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component&amp;#39;s functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application&amp;#39;s browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-10032</guid>
    </item>
    <item>
      <title>GHSA-72qq-p3r5-f7wq — @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-72qq-p3r5-f7wq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @a2ui/web_core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component&amp;#39;s `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application&amp;#39;s browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`).&lt;/p&gt;
&lt;p&gt;**Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`:&lt;/p&gt;
&lt;p&gt;```ts
export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args =&amp;gt; {
  if (args.url &amp;amp;&amp;amp; typeof window !== &amp;#39;undefined&amp;#39; &amp;amp;&amp;amp; window.open) {
    window.open(args.url, &amp;#39;_blank&amp;#39;);
  }
});
```&lt;/p&gt;
&lt;p&gt;`window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied.&lt;/p&gt;
&lt;p&gt;**Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`:&lt;/p&gt;
&lt;p&gt;```ts
export const OpenUrlApi = {
  name: &amp;#39;openUrl&amp;#39; as const,
  returnType: &amp;#39;void&amp;#39; as const,
  schema: z.object({
    url: z.preprocess(v =&amp;gt; (v === undefined ? undefined : String(v)), z.string()),
  }),
};
```&lt;/p&gt;
&lt;p&gt;The Zod schema only requires a `string`; `javas…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @a2ui/web_core&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component&amp;#39;s `functionCall` action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application&amp;#39;s browser origin, constituting a stored/reflected XSS. No non-default configuration is required; the Basic Catalog is enabled by default.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in the `openUrl` function implementation within the Basic Catalog of `@a2ui/web_core` (commit `23a003248abbf59da6c376ea64ace91d82d209ff`).&lt;/p&gt;
&lt;p&gt;**Sink** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions.ts:428-430`:&lt;/p&gt;
&lt;p&gt;```ts
export const OpenUrlImplementation = createFunctionImplementation(OpenUrlApi, args =&amp;gt; {
  if (args.url &amp;amp;&amp;amp; typeof window !== &amp;#39;undefined&amp;#39; &amp;amp;&amp;amp; window.open) {
    window.open(args.url, &amp;#39;_blank&amp;#39;);
  }
});
```&lt;/p&gt;
&lt;p&gt;`window.open` is called unconditionally with the agent-supplied `args.url` value. No scheme allowlist or blocklist is applied.&lt;/p&gt;
&lt;p&gt;**Insufficient schema validation** — `renderers/web_core/src/v0_9/basic_catalog/functions/basic_functions_api.ts:453-458`:&lt;/p&gt;
&lt;p&gt;```ts
export const OpenUrlApi = {
  name: &amp;#39;openUrl&amp;#39; as const,
  returnType: &amp;#39;void&amp;#39; as const,
  schema: z.object({
    url: z.preprocess(v =&amp;gt; (v === undefined ? undefined : String(v)), z.string()),
  }),
};
```&lt;/p&gt;
&lt;p&gt;The Zod schema only requires a `string`; `javas…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-72qq-p3r5-f7wq</guid>
    </item>
  </channel>
</rss>
