Product
AstronRPA versions 1.1.6 and earlier contain a cross-site scripting vulnerability in the smart-component chat that allows remote attackers to trigger arbitrary OS command execution by injecting malicious prompt content.