在 a2ui-project 的 a2ui 项目版本 0.10.7 及更早版本中发现了一个漏洞。该漏洞影响的是组件 FileResolver 中文件 的 函数。攻击者可通过操纵该函数触发服务器端请求伪造(SSRF)漏洞,并且该攻击可以远程发起。该漏洞的补丁标识符为 。为修复此问题,建议部署相应的安全补丁。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| a2ui-project | a2ui | 0.10.0 |
cpe:2.3:a:a2ui-project:a2ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92217 | 6.3 MEDIUM | a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-determi |
| CVE-2026-92213 | 5.5 MEDIUM | a2ui-project a2ui Angular Renderer server-to-client.ts z.any injection |
| CVE-2026-92216 | 4.3 MEDIUM | a2ui-project a2ui Binder generic-binder.ts openUrl redirect |
| CVE-2026-92214 | 3.5 LOW | a2ui-project a2ui a2a-chat-canvas sanitizer-markdown-renderer-service.ts cross site script |
No comments yet