CVE-2026-92216
A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
- EPSS probability
- 0.44%
- CWE
- CWE-601
- Published
- 2026-09-16
- Last modified
- 2026-09-16
Affected products
- a2ui-project a2ui
- a2ui-project a2ui
- a2ui-project a2ui
- a2ui-project a2ui
- a2ui-project a2ui
- a2ui-project a2ui
- a2ui-project a2ui
- a2ui-project a2ui
Weakness type
Related vulnerabilities
- CVE-2026-6795 — Open Redirect in DivvyDrive Information Technologies' DivvyDrive
- CVE-2026-54588 — Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
- CVE-2026-53662 — immich: One-click account takeover via XSS in login page continue redirect
- CVE-2026-43941 — Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click
- CVE-2026-61451 — Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
- CVE-2026-54618 — Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user
- CVE-2026-8323 — Open Redirect in Armiya Information Technologies' Access Control System
- CVE-2026-71428 — unstructured: Server-Side Request Forgery in the URL-based partitioning