This advisory has been withdrawn because it is a duplicate of GHSA-72qq-p3r5-f7wq. This link is maintained to preserve external references.
The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-02T22:55:15Z",
"nvd_published_at": "2026-08-04T16:16:20Z",
"severity": "MODERATE"
}