{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/astronrpa/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:astronrpa:astronrpa:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108159"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AstronRPA (\u003c= 1.1.6)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","xss"],"_cs_type":"advisory","_cs_vendors":["AstronRPA"],"content_html":"\u003cp\u003eAstronRPA desktop client versions up to and including 1.1.6 are susceptible to a critical cross-site scripting (XSS) vulnerability located within the smart-component chat feature. The application fails to sanitize output generated by an integrated Large Language Model (LLM) before rendering it using the v-html directive.\u003c/p\u003e\n\u003cp\u003eDefenders should note that this is not a standard client-side XSS; an attacker can embed specifically crafted prompt-injection content within a web page. When the AstronRPA client processes this content, the LLM is coerced into generating malicious HTML event handlers. These handlers exploit an insecure Inter-Process Communication (IPC) interface, allowing the application to execute OS commands with the privileges of the user running the desktop client. This impact is significant because it enables remote attackers to transition from malicious web content to arbitrary code execution on the local machine.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote attacker to execute arbitrary OS commands in the context of the user running the AstronRPA desktop application. This could lead to full system compromise, exfiltration of sensitive local data, or further lateral movement within the environment. All versions up to 1.1.6 are considered vulnerable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate identification of all endpoints running AstronRPA and coordinate with IT operations to restrict access to untrusted web content via the application until a patch is applied.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all instances of AstronRPA to the latest version beyond 1.1.6 as soon as a security update is provided by the vendor.\u003c/li\u003e\n\u003cli\u003eReview network logs for outbound connections from the AstronRPA process to unknown or suspicious domains if the environment allows restricting web content access for the tool.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual child processes spawned by the AstronRPA binary, such as cmd.exe, powershell.exe, or sh/bash, which are indicative of IPC-based command execution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T17:29:39Z","date_published":"2026-10-09T17:28:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-astronrpa-xss/","summary":"AstronRPA versions 1.1.6 and earlier contain a cross-site scripting vulnerability in the smart-component chat that allows remote attackers to trigger arbitrary OS command execution by injecting malicious prompt content.","title":"Remote Command Execution in AstronRPA via LLM-Driven XSS","url":"https://feed.craftedsignal.io/briefs/2026-10-astronrpa-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - AstronRPA","version":"https://jsonfeed.org/version/1.1"}