AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-494"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108160.json"
}