Server-Side Request Forgery Vulnerability in a2ui by a2ui-project
CVE-2026-92215

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92215?

A security flaw in the FileResolver component of a2ui (versions up to 0.10.7) allows for server-side request forgery through the httpx.get function in the file file_resolver.py. This vulnerability can be exploited remotely, potentially allowing an attacker to initiate unauthorized requests from the server to intranet resources. It is crucial to implement the necessary patch to mitigate this risk.

Affected Version(s)

a2ui 0.10.0

a2ui 0.10.1

a2ui 0.10.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

colorfullbz (VulDB User)
.