Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.1
CVE-2026-10032
- EPSS 0.2%
- Veröffentlicht 04.08.2026 15:36:45
- Zuletzt bearbeitet 23.09.2026 15:59:07
The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When th...
1