PT-2026-93256 · A2Ui · A2Ui
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
a2ui versions prior to 0.10.7
Description
A remote attack can be initiated against the Message Parsing component. The issue resides in the
processMessages() function within the renderers/web core/src/v0 9/processing/message-processor.ts file, where manipulation leads to dynamically-determined object attributes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the
processMessages() function to minimize the risk of exploitation. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
A2Ui