The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 02 Jun 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-06-02T00:00:00.000Z
Updated: 2025-06-02T14:13:30.990Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57783

Updated: 2025-06-02T14:13:14.824Z

Status : Awaiting Analysis
Published: 2025-06-02T14:15:21.170
Modified: 2025-06-02T17:32:17.397
Link: CVE-2024-57783

No data.