Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108159— AstronRPA through 1.1.6 RCE via Smart-Component Chat XSS and IPC Bridge

Quick assessment

Affected
iflytek astron-rpa
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AstronRPA 1.1.6 及之前版本在其桌面客户端的“智能组件聊天”功能中存在跨站脚本(XSS)漏洞。该漏洞允许远程攻击者通过滥用未经过消毒的大语言模型(LLM)输出内容(通过 v-html 渲染)来执行操作系统命令。攻击者可以在网页中嵌入提示词注入(prompt injection)内容,诱导模型生成包含 HTML 事件处理程序的代码,这些处理程序会调用不受限制的路径间通信(IPC)处理器,并传入 shell 元字符,从而以桌面用户的权限执行任意命令。

CVSS 7.5 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
iflytek astron-rpa ≤ 1.1.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108159

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AstronRPA through 1.1.6 RCE via Smart-Component Chat XSS and IPC Bridge
Source: CVE Program / CVE List V5
Vulnerability Description
AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
iflytek astron-rpa 0 ~ 1.1.6 -

II. Public POCs for CVE-2026-108159

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108159

请登录查看更多情报信息。

Other References for CVE-2026-108159 (4)

Same Patch Batch · iflytek · 2026-10-09 · 3 CVEs total

CVE-2026-108263 9.9 CRITICAL Astron Agent: Unsandboxed code-node leads to cross-tenant RCE
CVE-2026-108160 7.5 HIGH AstronRPA through 1.1.6 Unsigned Update Installation via Plain-HTTP Feed

IV. Related Vulnerabilities

V. Comments for CVE-2026-108159

No comments yet


Leave a comment