MinorCritical vulnerability
CVE-2026-108160 (CVSS 7.7)
NVD · officialPublished Oct 9, 2026Risk 23/100
AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user.
Technical details
CVSS
7.7
AV:NetworkAC:HighPR:NoneUI:Passive
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source