Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108160

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Oct 09, 2026
Vendor unknown

Description

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user.

References