← Blog · · df00tech

GHSA-72qq-p3r5-f7wq: Agent-Controlled `javascript:` URI Execution in @a2ui/web_core's openUrl Function

breaking ghsa npm CVE-2026-10032

What happened

A critical advisory (GHSA-72qq-p3r5-f7wq, CVE-2026-10032, CVSS 9.3) was published on 2026-10-02 against @a2ui/web_core, with a public proof-of-concept. The issue sits in the Basic Catalog's openUrl function implementation, which passes an agent-supplied url value directly to window.open() without validating the URI scheme. The Zod schema backing the function only enforces that url be a string, so a javascript: URI passes validation untouched. The flow runs from a Button component's functionCall action through the catalog invoker to the unguarded window.open sink, and is reproducible in all three bundled renderers (React, Lit, Angular) plus any other renderer that depends on web_core's basic catalog. No non-default configuration is required since the Basic Catalog is enabled by default.

Why it matters for defenders

This is a stored/reflected XSS vector delivered through an AI-agent UI framework: if an agent (or any upstream content source feeding agent-rendered UI) can control button action URLs, a single user click executes arbitrary JavaScript in the victim application's origin. That's full access to that origin's DOM, cookies, local storage, and any session tokens — a meaningful risk for any product embedding A2UI-rendered agent output in front of authenticated users. Because the flaw is in the default Basic Catalog rather than an opt-in feature, exposure is broad across adopters of @a2ui/web_core.

What defenders should watch for or do now

  • Inventory whether your frontend depends on @a2ui/web_core (directly or via React/Lit/Angular renderers) and check the installed version.
  • Upgrade to @a2ui/web_core 0.10.2 or later, which blocks non-HTTP/HTTPS and invalid URL schemes in the fix landed via PR #1707.
  • Until patched, consider disabling or sandboxing the Basic Catalog's Button/openUrl function for any agent whose output isn't fully trusted, or add a client-side scheme allowlist in front of calls into this function.
  • For hunting, review browser/application logs or CSP violation reports for javascript:-scheme navigation attempts originating from agent-rendered UI components, and audit any stored agent/button configuration data for embedded javascript: URLs.
  • Treat any third-party or agent-generated content rendered through A2UI as untrusted input requiring strict output encoding and scheme validation, not just this one function.

Developing intel

This advisory was published today and is based on the GHSA writeup and linked PR; details may be refined as the ecosystem responds. Treat this as early, developing intelligence and consult the original advisory for the authoritative technical writeup and fix: GHSA-72qq-p3r5-f7wq.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.