Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-69443 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all Archon information available on the UI including API keys.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-94Improper Control of Generation of Code ('Code Injection')CISA-ADP

Affected Products

ProductVersions
coleam00 Archon
>= 0.1.0, <= 0.3.11 (semver)

CPE

  • cpe:2.3:a:archon:archon:*:*:*:*:*:*:*:*
  • cpe:2.3:a:archon_project:archon:*:*:*:*:*:*:*:*

Remediation

  • Mitigation:low effort

    Bind port 8181 explicitly to 127.0.0.1 and restrict access via firewall rules.

  • Mitigation:low effort

    Do not store sensitive API keys in Archon until authentication is implemented on the backend.

  • Mitigation:low effort

    Avoid running unauthenticated local services that handle credentials or can act on your behalf.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-69443
NVD Published Date:
May 14, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]