Answer in brief
CVE-2026-108159 records a High severity (CVSS 7.7) vulnerability in AstronRPA through 1.1.6 RCE via Smart-Component Chat XSS and IPC Bridge. The current sources do not mark it as known exploited. The current feed maps iflytek/astron-rpa (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps iflytek/astron-rpa (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| iflytek/astron-rpageneric | >=0 <=1.1.6 | Not reported |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 9, 2026
AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user.
Quoted source text, attributed separately from HOL analysis.