Impact
A flaw in the Binder component users to arbitrary URLs. By supplying a crafted input, a remote actor can force the application to navigate to malicious sites, facilitating phishing or credential theft.
Affected Systems
The a2ui Project’s a2ui component, including the Binder module, in all releases up to and including 0.10.7 is affected.
Risk and Exploitability
The CVSS score of 5.3 reflects a medium severity vulnerability, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Attackers can exploit the issue remotely by invoking the vulnerable openUrl processing path without any authentication or additional controls. The risk is confined to redirects; it does not grant code execution or full system compromise.
OpenCVE Enrichment