CVE-2024-57783
Last modified
CVE-2024-57783 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.
Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-57783?
How severe is CVE-2024-57783?
How do I fix CVE-2024-57783?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-57775JFinalOA before v2025.01.01 was discovered to contain a SQL …8.8
- CVE-2024-57776A cross-site scripting (XSS) vulnerability in the /apply/get…4.6
- CVE-2024-57777Directory Traversal vulnerability in Ianproxy v.0.1 and befo…5.1
- CVE-2024-57778An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 …8.8
- CVE-2024-5778Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-57782An issue in Docker-proxy v18.09.0 allows attackers to cause …6.8
- CVE-2024-57784An issue in the component /php/script_uploads.php of Zenitel…5.5
- CVE-2024-57785Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a l…4.9
- CVE-2024-5779Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-57790IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was…5.4
- CVE-2024-57791In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2024-57792In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2024-57783?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
