CVE-2026-92216 MEDIUM

CVE-2026-92216: a2ui-project a2ui Binder generic-binder.ts openUrl redirect

Vendor A2Ui-Project
Product a2ui
Weakness CWE-601 · Open redirect
Published September 16, 2026
Last update September 16, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.

Key dates

02Disclosure timeline

September 16, 2026 CVE published