CVE-2026-92213

Summary

A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argument primaryColor results in injection. The attack is possible to be carried out remotely. The patch is named fb8e85aec78d04e81feb9992a57638ca1ec4dc1b. It is suggested to install a patch to address this issue.

Affected Software

VendorProductVersion RangeStatus
a2ui-projecta2ui0.10.0affected
a2ui-projecta2ui0.10.1affected
a2ui-projecta2ui0.10.2affected
a2ui-projecta2ui0.10.3affected
a2ui-projecta2ui0.10.4affected
a2ui-projecta2ui0.10.5affected
a2ui-projecta2ui0.10.6affected

Weaknesses

  • CWE-74: Injection
  • CWE-707: Improper Neutralization

References