CVE-2026-92217: a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-determined object attributes
A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/webcore/src/v09/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determined object attributes. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The affected component is Message Parsing in a2ui-project a2ui, specifically processMessages in renderers/web_core/src/v0_9/processing/message-processor.ts. Versions up to and including 0.10.6 are identified as affected.
What level of access does an attacker need?
The issue can be initiated remotely and has low attack complexity. The supplied vector indicates that the attacker needs low privileges and does not require user interaction.
What is the potential impact?
The provided severity vector indicates low impact to confidentiality, integrity, and availability. Scope is unchanged.
Is a fix available from the project?
The project was reportedly notified early through an issue report but had not responded at the time of the provided information. No fixed version or workaround is identified in the available data.