{"id":"CVE-2026-108160","summary":"AstronRPA through 1.1.6 Unsigned Update Installation via Plain-HTTP Feed","details":"AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user.","modified":"2026-10-10T10:30:43.429552132Z","published":"2026-10-09T16:04:44.290Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-494"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108160.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108160.json"},{"type":"PACKAGE","url":"https://github.com/iflytek/astron-rpa"},{"type":"ARTICLE","url":"https://github.com/iflytek/astron-rpa/blob/8b015bc1b15d23fbdc55c78ff1de9af4bb65fba6/frontend/packages/electron-app/electron-builder.json#L26"},{"type":"REPORT","url":"https://github.com/iflytek/astron-rpa/issues/894"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-108160"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/astronrpa-through-1.1.6-unsigned-update-installation-via-plain-http-feed"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/iflytek/astron-rpa","events":[{"introduced":"0"},{"last_affected":"8b015bc1b15d23fbdc55c78ff1de9af4bb65fba6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.1.6"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.1.6","v1.1.5","v1.1.2-nightly","v1.0.0","v0.1.0-alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108160.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}