Message Parsing Vulnerability in a2ui by a2ui-project
CVE-2026-92217
5.3MEDIUM
What is CVE-2026-92217?
A critical security issue has been identified in the a2ui project, specifically within the Message Parsing component. The vulnerability lies in the 'processMessages' function of 'renderers/web_core/src/v0_9/processing/message-processor.ts', which can lead to the manipulation of dynamically-determined object attributes. This flaw allows for remote exploitation, posing significant risks to the integrity and confidentiality of data processed by the application. Despite early notifications regarding the issue via an issue report, the project maintainers have yet to address this vulnerability.
Affected Version(s)
a2ui 0.10.0
a2ui 0.10.1
a2ui 0.10.2
