Message Parsing Vulnerability in a2ui by a2ui-project
CVE-2026-92217

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92217?

A critical security issue has been identified in the a2ui project, specifically within the Message Parsing component. The vulnerability lies in the 'processMessages' function of 'renderers/web_core/src/v0_9/processing/message-processor.ts', which can lead to the manipulation of dynamically-determined object attributes. This flaw allows for remote exploitation, posing significant risks to the integrity and confidentiality of data processed by the application. Despite early notifications regarding the issue via an issue report, the project maintainers have yet to address this vulnerability.

Affected Version(s)

a2ui 0.10.0

a2ui 0.10.1

a2ui 0.10.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

colorfullbz (VulDB User)
VulDB CNA Team
.