CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core
Vulnerability ID: CVE-2026-10032
CVSS Score: 6.1
Published: 2026-10-02
CVE-2026-10032 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Google's @a2ui/web_core Node.js library. The vulnerability is located within the openUrl utility function, which processes and opens dynamic URLs defined in layout configurations. Because the function fails to sanitize or validate the target URL scheme before passing it to the window.open browser sink, an attacker can specify a javascript: pseudo-protocol to execute arbitrary client-side script in the context of the host origin.
TL;DR
Unvalidated URL configuration parameter passing to the window.open sink within the @a2ui/web_core layout engine enables unauthenticated remote attackers to execute arbitrary JavaScript in the victim browser origin.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-79
- Attack Vector: Network (AV:N)
- CVSS Score: 6.1 (Medium)
- EPSS Score: 0.00130 (Percentile: 2.227%)
- Impact: Execution of arbitrary JavaScript under victim origin (XSS)
- Exploit Status: PoC Available
- KEV Status: Not Listed
Affected Systems
- @a2ui/web_core npm library
-
@a2ui/web_core: >= 0.9.0, < 0.10.2 (Fixed in:
0.10.2)
Code Analysis
Commit: 7157307
Implement safe URL validation inside the openUrl execution engine using WHATWG URL class and protocol filtering.
Exploit Details
- Advisory Proof-of-Concept: The advisory outlines JSON configuration payloads leveraging 'javascript:' URIs inside the 'args.url' parameter of 'openUrl' to achieve XSS.
Mitigation Strategies
- Upgrade @a2ui/web_core dependency to version 0.10.2 or higher.
- Implement a Content Security Policy (CSP) that restricts 'unsafe-inline' scripts.
- Validate and sanitize layout JSON configurations on the server-side before serving them to clients.
- Ensure all window opening implementations enforce 'noopener,noreferrer' attributes to mitigate reverse tab-nabbing.
Remediation Steps:
- Open the package.json file of your project.
- Locate the '@a2ui/web_core' dependency entry under dependencies.
- Update the version string to '^0.10.2'.
- Run 'npm install' or 'yarn install' to pull the patched version.
- Validate the upgrade by executing security test suites against layout renderers.
References
Read the full report for CVE-2026-10032 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)