Vulnerability  ·  2026-10-10

AstronRPA smart-component chat: prompt-injected LLM output leads to OS command execution via v-html XSS + IPC bridge (CVSS 7.5)

VulnerabilityHigh impactGlobalCVE-2026-108159
Verified via NVD REST API (published 2026-10-09 by VulnCheck): AstronRPA <= 1.1.6 contains an XSS in the desktop client's smart-component chat driven by unsanitized LLM output rendered through v-html. An attacker can plant prompt-injection content that makes the model emit HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing OS commands as the desktop user (CWE-79).
The chain is prompt injection → stored/indirect XSS → unrestricted IPC → OS RCE inside a desktop RPA agent, a concrete real-world realisation of 'LLM output as an attack vector' against deployed agentic automation. It matters because RPA agents hold broad local permissions and process attacker-influenced content by design.
Authenticated-prompt-injection path: attacker embeds prompt-injection content in a web page or document the RPA agent processes; the model's unsanitized output is rendered via v-html with HTML event handlers that invoke the desktop app's unrestricted open-path IPC handler carrying shell metacharacters, executing commands as the desktop user.
iflytek/astron-rpa <= 1.1.6 (desktop RPA client smart-component chat)
Vendor issue tracker: https://github.com/iflytek/astron-rpa/issues/892 — no patched release confirmed; mitigate by sanitising/escaping LLM output before v-html rendering and restricting the IPC open-path handler. VulnCheck advisory: https://www.vulncheck.com/advisories/astronrpa-through-1.1.6-rce-via-smart-component-chat-xss-and-ipc-bridge
NVD CVE-2026-108159VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →