CVE-2026-108160
Deferred Deferred - Pending Action

AstronRPA Auto-Update Code Execution Vulnerability

Vulnerability report for CVE-2026-108160, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iflytek astron-rpa 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AstronRPA versions up to 1.1.6 have a vulnerability where the auto-update mechanism does not verify the integrity of update files. Attackers between the client and server can replace legitimate updates with malicious ones, leading to arbitrary code execution on the user's system.

Detection Guidance

Check if AstronRPA's auto-update mechanism uses unsigned updates by inspecting the electron-builder.json configuration for verifyUpdateCodeSignature set to false. Monitor network traffic for unencrypted HTTP update feeds, especially if the feed URL in conf.yaml points to http://127.0.0.1:32742/. Look for unexpected NSIS installer executions or unusual update manifests.

Impact Analysis

If exploited, this vulnerability allows attackers to execute malicious code on your system by intercepting and replacing software updates. This could lead to data theft, system compromise, or further network attacks.

Compliance Impact

This vulnerability could violate compliance requirements that mandate secure software updates and data integrity, such as GDPR's security principles or HIPAA's safeguards for protecting sensitive data.

Mitigation Strategies

Enable signature verification in electron-builder.json by setting verifyUpdateCodeSignature to true. Switch the update feed from HTTP to HTTPS to prevent interception. Block or restrict access to the default update feed URL if it uses localhost or untrusted sources. Update AstronRPA to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108160. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart