CVE-2026-108159
Deferred Deferred - Pending Action

XSS in AstronRPA Desktop Client via LLM Output

Vulnerability report for CVE-2026-108159, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iflytek astron-rpa 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AstronRPA through version 1.1.6 has a cross-site scripting flaw in its desktop client's smart-component chat. This allows remote attackers to execute operating system commands by exploiting unsanitized LLM output rendered via v-html. Attackers can inject prompt content into a web page that causes the model to emit HTML event handlers. These handlers invoke an unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user.

Detection Guidance

To detect this vulnerability, inspect the AstronRPA desktop client's chat functionality for unsanitized HTML output. Check if the application renders AI responses via v-html without proper sanitization. Look for IPC handlers like open-path being exposed to the renderer process. Monitor for unexpected OS command execution traces in logs or system processes.

Impact Analysis

This vulnerability allows attackers to run arbitrary OS commands on your system if you use AstronRPA desktop client. They could steal data, install malware, or take control of your computer. The attack requires tricking you into visiting a malicious web page or interacting with crafted content.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using AstronRPA may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Update AstronRPA to the latest version beyond 1.1.6 to patch the XSS vulnerability in the smart-component chat. Disable HTML rendering in the desktop client if possible or restrict unsanitized LLM output. Monitor for unusual command execution patterns or unauthorized IPC handler invocations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108159. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart