Impact
A2UI's Angular Renderer is vulnerable through its A manipulation of the primaryColor argument allows an attacker to inject arbitrary content, leading to potential code execution or other malicious payloads. The flaw is an injection vulnerability, as indicated by the CWE identifiers 707 and 74.
Affected Systems
The vulnerability affects a2ui-project's a2ui component up to version 0.10.6. It is present in the Angular Renderer’s server‑to‑client code and is patched in the commit fb8e85aec78d04e81feb9992a57638ca1ec4dc1b.
Risk and Exploitability
The CVSS v3.1 score of 5.1 classifies the flaw as moderately severe. The EPSS score of less than 1% suggests a low exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalogue. Attacks are possible remotely, implying that any system exposing the Angular Renderer could be targeted.
OpenCVE Enrichment