AstronRPA 1.1.6 及之前版本在其桌面客户端的“智能组件聊天”功能中存在跨站脚本(XSS)漏洞。该漏洞允许远程攻击者通过滥用未经过消毒的大语言模型(LLM)输出内容(通过 v-html 渲染)来执行操作系统命令。攻击者可以在网页中嵌入提示词注入(prompt injection)内容,诱导模型生成包含 HTML 事件处理程序的代码,这些处理程序会调用不受限制的路径间通信(IPC)处理器,并传入 shell 元字符,从而以桌面用户的权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| iflytek | astron-rpa | ≤ 1.1.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| iflytek | astron-rpa | 0 ~ 1.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108263 | 9.9 CRITICAL | Astron Agent: Unsandboxed code-node leads to cross-tenant RCE |
| CVE-2026-108160 | 7.5 HIGH | AstronRPA through 1.1.6 Unsigned Update Installation via Plain-HTTP Feed |
No comments yet