Impact
The vulnerability lies in an unprotected function within model-processor.ts. By manipulating the argument current[segment], an attacker can trigger the disclosure of sensitive information. The flaw is an information disclosure (CWE‑200) that also involves inadequate authorization controls (CWE‑284). Attackers can initiate the exploit remotely, although the exact remote entry point is not explicitly documented in the input.
Affected Systems
The affected software is a2ui-project a2ui versions 0.8, 0.9, and 1.0. These can be identified by the CPE a2ui-project:a2ui.* and represent the Model Processor component of the a2ui project.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, while the EPSS score of less than 1% suggests a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Because the description states the attack may be initiated remotely, the likely attack vector is over the network to a vulnerable endpoint that processes the current[segment] argument.
OpenCVE Enrichment