CVE-2026-92214
Deferred Deferred - Pending Action

Cross-Site Scripting in a2ui a2a-chat-canvas

Vulnerability report for CVE-2026-92214, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-22

Assigner: VulDB

Description

A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-22
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
a2ui-project a2ui to 0.10.7 (inc)
a2a-chat-canvas a2a-chat-canvas to 0.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in the a2ui-project a2ui up to version 0.10.7. It exists in the a2a-chat-canvas sample project where a function in the file sanitizer-markdown-renderer-service.ts bypasses Angular's HTML sanitization. This allows raw HTML input to be rendered directly in the host application, enabling attackers to inject malicious scripts via manipulated input.

Detection Guidance

To detect this vulnerability, inspect Angular applications using the a2a-chat-canvas component for usage of sanitizer.bypassSecurityTrustHtml() combined with @HostBinding('innerHTML'). Check files like sanitizer-markdown-renderer-service.ts for raw HTML rendering without proper sanitization. Review sample code in the repository for unsafe patterns.

Impact Analysis

If you use the affected sample code in your application, an attacker could execute malicious scripts in the context of your application. This could lead to theft of user data, session hijacking, or defacement of your application. The impact depends on the application's context and user privileges.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, non-compliance with privacy regulations, and potential legal consequences depending on the data processed by the affected application.

Mitigation Strategies

Replace the default text renderer with a sanitizing pipeline using @a2ui/markdown-it with html: false and DOMPurify. Avoid using sanitizer.bypassSecurityTrustHtml() for untrusted input. Update affected files: sanitizer-markdown-renderer-service.ts, default-text-part.ts, markdown-renderer-service.ts, and config.ts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92214. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart