CVE-2026-92217

Summary

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determined object attributes. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
a2ui-projecta2ui0.10.0affected
a2ui-projecta2ui0.10.1affected
a2ui-projecta2ui0.10.2affected
a2ui-projecta2ui0.10.3affected
a2ui-projecta2ui0.10.4affected
a2ui-projecta2ui0.10.5affected
a2ui-projecta2ui0.10.6affected

Weaknesses

  • CWE-915: Dynamically-Determined Object Attributes
  • CWE-913: Dynamically-Managed Code Resources

References