Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-08-03

HighPrimary

A2UI Agent-Supplied Button Lets a JavaScript URI Execute in the Application Origin

Analysis of CVE-2026-10032, where A2UI web_core accepted an agent-supplied javascript URI and executed it in the application origin after a user clicked a rendered button.

A2UITool execution / MCPAgent-supplied action URI executed without scheme validation@a2ui/web_core 0.9.0 through 0.10.1 using the default Basic Catalog, including the repository's React, Lit, and Angular renderers

What happened

In the disclosed demonstration, a malicious agent supplies a Button functionCall whose openUrl argument uses the javascript: scheme; a user click dispatches that action and executes the supplied script in the application origin.

Why it matters

Potential theft or modification of data available to the victim application origin after the user clicks the attacker-defined button. No real-world exploitation is reported.

Missing authorization check

Renderer-side validation and authorization over the canonical function, URI scheme, destination, application origin, and user interaction before dispatching an agent-supplied browser action.

Would PP block it?

An independently controlled gate integrated by the victim application could restrict openUrl to approved HTTP and HTTPS destinations, but that is a defensive deployment outside the attacker-operated agent. Permission Protocol should not be claimed to prevent the underlying A2UI flaw.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-03

    GitHub publishes GHSA-72qq-p3r5-f7wq for the A2UI openUrl scheme-validation flaw.

  2. 2026-08-05

    The advisory is updated to identify @a2ui/web_core 0.10.2 as the first fixed release.

Technical breakdown

  • A Button action can carry a functionCall with an agent-controlled url argument.
  • The openUrl schema accepted any string and did not restrict the URI scheme.
  • The default Basic Catalog passed the value directly to window.open after the user clicked the rendered button.
  • React, Lit, and Angular renderers in the A2UI repository shared the vulnerable action path.
  • The fix rejects invalid URLs and schemes other than HTTP and HTTPS.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Victim application's A2UI action dispatcher immediately before executing openUrl
Still needs
Permission Protocol does not repair A2UI scheme validation, sanitize attacker-generated UI, prevent a user from clicking the button, or contain JavaScript once the browser executes it. Upgrading to 0.10.2 or later remains necessary.
Receipt required for
Dispatching the exact agent-supplied function and canonical URL in a named application origin

The demonstrated agent is attacker-operated, so Permission Protocol cannot establish trustworthy authority inside that malicious workflow or replace the renderer's required URI validation.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop