Home
Description
Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all Archon information available on the UI including API keys.
References
www.ox.security/blog/archon-remote-code-execution
www.ox.security/...-to-unauthenticated-web-to-client-attack/