Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argument primaryColor results in injection. The attack is possible to be carried out remotely. The patch is named fb8e85aec78d04e81feb9992a57638ca1ec4dc1b. It is suggested to install a patch to address this issue. | |
| Title | a2ui-project a2ui Angular Renderer server-to-client.ts z.any injection | |
| First Time appeared |
A2ui-project
A2ui-project a2ui |
|
| Weaknesses | CWE-707 CWE-74 |
|
| CPEs | cpe:2.3:a:a2ui-project:a2ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
A2ui-project
A2ui-project a2ui |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-16T00:00:24.104Z
Reserved: 2026-09-15T18:28:56.437Z
Link: CVE-2026-92213
No data.
Status : Received
Published: 2026-09-16T01:16:29.247
Modified: 2026-09-16T01:16:29.247
Link: CVE-2026-92213
No data.
OpenCVE Enrichment
No data.