The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-02T14:13:30.990Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57783
Updated: 2025-06-02T14:13:14.824Z
Status : Deferred
Published: 2025-06-02T14:15:21.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-57783
No data.
OpenCVE Enrichment
No data.