36f2972150
GHSA-72qq-p3r5-f7wq (CVSS 9.3). web_core <= 0.10.1 passed an agent-supplied `openUrl` argument straight to `window.open()` with no scheme allowlist, so a Button whose `functionCall` named a `javascript:` URI executed arbitrary script in the host origin when a user clicked it. The Basic Catalog is the default, so no non-default configuration was required to be exposed. We pinned 0.9.0 exactly, as a runtime dependency of two published packages (@copilotkit/a2ui-renderer, @copilotkit/vue) and transitively of @copilotkit/react-core and @copilotkit/angular, so downstream users could not upgrade out of it on their own. 0.10.4 keeps the ./v0_9 and ./v0_9/basic_catalog entrypoints we import; the only symbol dropped from v0_9 is FrameworkSignal, which we never referenced. Add regression tests over both renderers that reach the sink independently (React and Lit). They assert that javascript: and data: URIs never reach window.open, that https URLs still open with noopener,noreferrer, and that a blocked scheme leaves the surface mounted rather than escaping into the click handler. Verified they fail against 0.9.0 and pass against 0.10.4.