Impact
The vulnerability resides in the processMessages function of message-processor.ts, part of the Message Parsing component. An attacker can craft messages that set object attributes dynamically without proper validation, allowing the application to assign properties it normally would not. This can result in unintended changes to internal data structures. The CVE description does not indicate remote code execution or privilege escalation; it focuses on the ability to alter application state.
Affected Systems
Deployments that include the a2ui-project a2ui package version 0.10.6 or earlier are affected. The vulnerable code appears in renderers/web_core/src/v0_9/processing/message-processor.ts. Any environment that exposes this endpoint to external input via WebSocket or REST API may be impacted. Versions newer than 0.10.6 are not listed as vulnerable in the provided data.
Risk and Exploitability
The CVSS base score of 5.3 places this issue in the medium risk range, while the EPSS score of less than 1 % indicates a very low but non‑zero probability of exploitation as of the latest data. The vulnerability is not listed in CISA's KEV catalog, and no public exploit code is available. Exploitation requires remote access to the message parsing endpoint and the ability to send crafted messages to manipulate internal object properties. The lack of a publicly released patch underscores the importance of assessing exposure and mitigating with the steps below.
OpenCVE Enrichment