在 a2ui-project 的 a2ui 0.9 和 0.9.1 版本中,发现了一个安全漏洞。该问题影响 文件中 函数(位于“Update Components”组件内)。执行特定操作可能导致资源消耗(Resource Consumption),即可能引发内存或 CPU 等资源的过度占用。该攻击可以远程发起。项目方已通过问题报告早期获知此问题,但尚未作出响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| a2ui-project | a2ui | 0.9 |
cpe:2.3:a:a2ui-project:a2ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92215 | 7.3 HIGH | a2ui-project a2ui FileResolver file_resolver.py httpx.get server-side request forgery |
| CVE-2026-92217 | 6.3 MEDIUM | a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-determi |
| CVE-2026-92213 | 5.5 MEDIUM | a2ui-project a2ui Angular Renderer server-to-client.ts z.any injection |
| CVE-2026-92216 | 4.3 MEDIUM | a2ui-project a2ui Binder generic-binder.ts openUrl redirect |
| CVE-2026-92357 | 4.3 MEDIUM | a2ui-project a2ui Model Processor model-processor.ts information disclosure |
| CVE-2026-92214 | 3.5 LOW | a2ui-project a2ui a2a-chat-canvas sanitizer-markdown-renderer-service.ts cross site script |
No comments yet