CVE-2024-57783

HIGH

Dot <0.9.3 - XSS

Title source: llm
STIX 2.1

Description

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

Scores

CVSS v3 8.1
EPSS 0.0006
EPSS Percentile 18.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
alexpinel/Dot < 0.9.3
Published Jun 02, 2025
Tracked Since Feb 18, 2026