CVE-2026-92217
Received Received - Intake

Prototype Pollution in a2ui up to 0.10.6

Vulnerability report for CVE-2026-92217, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: VulDB

Description

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determined object attributes. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
a2ui-project a2ui to 0.10.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CWE-913 The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the a2ui project up to version 0.10.6, specifically in the message processor for version 0.9. The issue is that the processor does not validate incoming message envelopes against the v0.9 JSON schema, unlike the v0.8 processor. Additionally, components with unknown types are not properly validated but are still committed to the components model and trigger events. This occurs in the file renderers/web_core/src/v0_9/processing/message-processor.ts.

Detection Guidance

Check if your a2ui version is up to 0.10.6 or earlier. Inspect logs for message processing errors in renderers/web_core/src/v0_9/processing/message-processor.ts. Monitor for components with unknown types being committed to the components model without validation.

Impact Analysis

This vulnerability allows attackers to inject malicious payloads through components with unknown types. These components are accepted and stored without validation, creating a gap in security. Any consumer of the components model inherits unvalidated properties controlled by the attacker. While current renderers do not render unknown types, the issue poses a risk for any system relying on the components model.

Mitigation Strategies

Upgrade to the latest version of a2ui if available. Implement schema validation for incoming messages in the v0.9 message processor. Reject or strictly validate components with unknown types not listed in configured catalogs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92217. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart