Skip to content
Security & Trust

An AI agent's button could run attacker code in apps using an A2UI library

A flaw in @a2ui/web_core shows why an agent's output needs the same checks as a stranger's input

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
An AI agent's button could run attacker code in apps using an A2UI library

AI-generated image for WebPulse. About our images

In brief
  • GitHub's advisory says @a2ui/web_core let an agent-supplied button action run a javascript: link as code in the host app's browser origin.
  • The library treated the agent's output as trusted, although web developers long ago learned not to trust outside input.
  • Teams should find any use of @a2ui/web_core, confirm version 0.10.2 or later, and ask which agents can send interface instructions to their apps.

When software lets an AI agent design the screen, the agent's output stops being content. It becomes instructions. A flaw in one user-interface library shows what that trust can cost.

The GitHub Advisory Database published the issue on October 2, 2026. It affects @a2ui/web_core, a JavaScript library that turns agent instructions into on-screen components such as buttons. The advisory points to CVE-2026-10032 on the NVD, the US government's vulnerability database.

What went wrong

An agent can attach an action to a Button component. One action calls a function named openUrl. That function passes the agent's URL straight to window.open(), the browser call that opens a link. It never checks what kind of link it received.

A javascript: link is not a web address. It is code that the browser runs. If an agent supplies one, a click on the button runs that code inside the host application's browser origin. The origin is the app's own identity and permissions in the browser.

The advisory describes this as stored or reflected cross-site scripting (XSS), a long-known class of flaw in which attacker-supplied code runs inside a trusted page.

A second check should have caught it. The library validates the URL with a schema that only requires a string. A javascript: link is a string, so it passes.

3
Renderers affected
Source: GitHub Advisory Database, GHSA-72qq-p3r5-f7wq (October 2, 2026)

The advisory says all three renderers in the A2UI repository are affected: React, Lit and Angular. Renderers written by others are not spared. Any that build on web_core and rely on its basic catalog inherit the same weakness.

Nothing unusual has to be switched on. The basic catalog is enabled out of the box.

The idea behind the bug

Web developers learned long ago not to trust input that arrives from outside. Here the library treated the agent's output as trusted. It ran the agent's URL without asking what it was.

That is the shift for leaders to notice. Agents now write parts of the screen, not only the answers behind it. Each piece of that output is input to your application. It needs the same checks as anything a stranger sends.

The advisory speaks of a malicious agent. It does not say how an agent might become malicious, and it reports no attacks in the wild. The risk it documents is the missing check, not a known campaign.

The fix and who is exposed

The maintainers fixed the issue in a2ui-project/a2ui#1707 and released it in web_core version 0.10.2. The fix blocks any URL that is invalid or does not use HTTP or HTTPS. The advisory asks users to depend on version 0.10.2 or later.

0.10.2
Fixed version of @a2ui/web_core
Source: GitHub Advisory Database, GHSA-72qq-p3r5-f7wq (October 2, 2026)
2 (HTTP and HTTPS)
URL schemes allowed after the fix
Source: GitHub Advisory Database, GHSA-72qq-p3r5-f7wq (October 2, 2026)

Note the fix is an allowlist. It names the two safe schemes and rejects everything else. That is a sturdier design than trying to list every dangerous one.

Questions to put to your team

Do any products we build or buy depend on @a2ui/web_core, and is the version 0.10.2 or later? Ask vendors as well as engineers, since the library may sit inside a product you did not write.

Which agents can send interface instructions to our applications? Who controls them, and are any run by third parties?

Do we validate what an agent sends the way we validate what a customer types? If the answer differs, ask why.

An agent that draws your button is a stranger handing you a pen. Check what it writes before anyone clicks.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: GitHub Advisory Database.

CVEs in this analysis
CVE-2026-10032
Compare frameworks in this analysis
React vs Angular
Share this insight