CVE-2026-92216

Summary

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
a2ui-projecta2ui0.10.0affected
a2ui-projecta2ui0.10.1affected
a2ui-projecta2ui0.10.2affected
a2ui-projecta2ui0.10.3affected
a2ui-projecta2ui0.10.4affected
a2ui-projecta2ui0.10.5affected
a2ui-projecta2ui0.10.6affected
a2ui-projecta2ui0.10.7affected

Weaknesses

  • CWE-601: Open Redirect

References