{"id":"CVE-2026-108159","summary":"AstronRPA through 1.1.6 RCE via Smart-Component Chat XSS and IPC Bridge","details":"AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user.","modified":"2026-10-11T02:46:57.557115826Z","published":"2026-10-09T16:04:42.687Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108159.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108159.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-108159"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/astronrpa-through-1.1.6-rce-via-smart-component-chat-xss-and-ipc-bridge"},{"type":"REPORT","url":"https://github.com/iflytek/astron-rpa/issues/892"},{"type":"PACKAGE","url":"https://github.com/iflytek/astron-rpa"},{"type":"ARTICLE","url":"https://github.com/iflytek/astron-rpa/blob/8b015bc1b15d23fbdc55c78ff1de9af4bb65fba6/frontend/packages/web-app/src/components/SmartComponent/hooks/useChatContext.tsx#L203"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/iflytek/astron-rpa","events":[{"introduced":"0"},{"fixed":"8b015bc1b15d23fbdc55c78ff1de9af4bb65fba6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.1.6"},{"fixed":"1.1.6"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v1.1.5","v1.1.2-nightly","v1.0.0","v0.1.0-alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108159.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}