Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54618 | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. |
Mon, 02 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-02T14:13:30.990Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57783
Updated: 2025-06-02T14:13:14.824Z
Status : Deferred
Published: 2025-06-02T14:15:21.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-57783
No data.
OpenCVE Enrichment
No data.
EUVD