CVE-2026-92214: a2ui-project a2ui a2a-chat-canvas sanitizer-markdown-renderer-service.ts cross site scripting
A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using a2ui-project/a2ui versions up to 0.10.7 and the a2a-chat-canvas component are in scope, specifically the Angular sample path containing sanitizer-markdown-renderer-service.ts.
What does an attacker need to exploit it?
The attack can be performed remotely, but the CVSS vector indicates the attacker requires low-level privileges and user interaction. The reported outcome is cross-site scripting with low integrity impact and no reported confidentiality or availability impact.
How can I determine whether my deployment is affected?
Check whether your a2ui-project/a2ui version is 0.10.7 or earlier and whether you use the a2a-chat-canvas Angular sample/component containing samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts.