What happened
In the disclosed demonstration, a malicious agent supplies a Button functionCall whose openUrl argument uses the javascript: scheme; a user click dispatches that action and executes the supplied script in the application origin.
2026-08-03
HighPrimaryAnalysis of CVE-2026-10032, where A2UI web_core accepted an agent-supplied javascript URI and executed it in the application origin after a user clicked a rendered button.
What happened
In the disclosed demonstration, a malicious agent supplies a Button functionCall whose openUrl argument uses the javascript: scheme; a user click dispatches that action and executes the supplied script in the application origin.
Why it matters
Potential theft or modification of data available to the victim application origin after the user clicks the attacker-defined button. No real-world exploitation is reported.
Missing authorization check
Renderer-side validation and authorization over the canonical function, URI scheme, destination, application origin, and user interaction before dispatching an agent-supplied browser action.
Would PP block it?
An independently controlled gate integrated by the victim application could restrict openUrl to approved HTTP and HTTPS destinations, but that is a defensive deployment outside the attacker-operated agent. Permission Protocol should not be claimed to prevent the underlying A2UI flaw.
Incident analysis
2026-08-03
GitHub publishes GHSA-72qq-p3r5-f7wq for the A2UI openUrl scheme-validation flaw.
2026-08-05
The advisory is updated to identify @a2ui/web_core 0.10.2 as the first fixed release.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
The demonstrated agent is attacker-operated, so Permission Protocol cannot establish trustworthy authority inside that malicious workflow or replace the renderer's required URI validation.
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.