Home

Description

Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all Archon information available on the UI including API keys.

PUBLISHED Reserved 2026-01-09 | Published 2026-05-14 | Updated 2026-05-15 | Assigner mitre

References

github.com/coleam00/Archon

www.ox.security/blog/archon-remote-code-execution

www.ox.security/...-to-unauthenticated-web-to-client-attack/

cve.org (CVE-2025-69443)

nvd.nist.gov (CVE-2025-69443)

Download JSON