Open Redirect Vulnerability in a2ui Project by a2ui
CVE-2026-92216

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92216?

A vulnerability exists in the a2ui project within its openUrl function located in the generic-binder.ts file. This flaw allows for open redirection, enabling potential attackers to redirect users to malicious sites from a legitimate domain. Exploitation of this vulnerability can be conducted remotely, increasing its risk factor. Despite an early notification regarding this issue through an issue report, the a2ui project has not yet addressed the vulnerability.

Affected Version(s)

a2ui 0.10.0

a2ui 0.10.1

a2ui 0.10.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

colorfullbz (VulDB User)
VulDB CNA Team
.