Description
The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54618 | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. |
References
History
Mon, 02 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-02T14:13:30.990Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57783
Updated: 2025-06-02T14:13:14.824Z
Status : Deferred
Published: 2025-06-02T14:15:21.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-57783
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD