<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>AstronRPA (&lt;= 1.1.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/astronrpa--1.1.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 17:28:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/astronrpa--1.1.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Execution in AstronRPA via LLM-Driven XSS</title><link>https://feed.craftedsignal.io/briefs/2026-10-astronrpa-xss/</link><pubDate>Fri, 09 Oct 2026 17:28:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-astronrpa-xss/</guid><description>AstronRPA versions 1.1.6 and earlier contain a cross-site scripting vulnerability in the smart-component chat that allows remote attackers to trigger arbitrary OS command execution by injecting malicious prompt content.</description><content:encoded><![CDATA[<p>AstronRPA desktop client versions up to and including 1.1.6 are susceptible to a critical cross-site scripting (XSS) vulnerability located within the smart-component chat feature. The application fails to sanitize output generated by an integrated Large Language Model (LLM) before rendering it using the v-html directive.</p>
<p>Defenders should note that this is not a standard client-side XSS; an attacker can embed specifically crafted prompt-injection content within a web page. When the AstronRPA client processes this content, the LLM is coerced into generating malicious HTML event handlers. These handlers exploit an insecure Inter-Process Communication (IPC) interface, allowing the application to execute OS commands with the privileges of the user running the desktop client. This impact is significant because it enables remote attackers to transition from malicious web content to arbitrary code execution on the local machine.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a remote attacker to execute arbitrary OS commands in the context of the user running the AstronRPA desktop application. This could lead to full system compromise, exfiltration of sensitive local data, or further lateral movement within the environment. All versions up to 1.1.6 are considered vulnerable.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate identification of all endpoints running AstronRPA and coordinate with IT operations to restrict access to untrusted web content via the application until a patch is applied.</p>
<ul>
<li>Update all instances of AstronRPA to the latest version beyond 1.1.6 as soon as a security update is provided by the vendor.</li>
<li>Review network logs for outbound connections from the AstronRPA process to unknown or suspicious domains if the environment allows restricting web content access for the tool.</li>
<li>Monitor for unusual child processes spawned by the AstronRPA binary, such as cmd.exe, powershell.exe, or sh/bash, which are indicative of IPC-based command execution.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>xss</category></item></channel></rss>