CVE-2025-69443 Details
Description
Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all Archon information available on the UI including API keys.
A remote code execution vulnerability exists in Archon version 0.1.0. This issue allows a crafted HTML page, when accessed by a user, to execute commands and prompts on their behalf. The vulnerability also enables control over Archon's UI features and access to all Archon information displayed on the UI, including API keys.
Users are advised not to expose Archon's backend port 8181 externally and to bind it explicitly to localhost. Additionally, sensitive API keys should not be stored in Archon until authentication is implemented on the backend.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2026CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/coleam00/Archon | [email protected] | ProductSource CodeVendor |
| https://www.ox.security/blog/archon-remote-code-execution | [email protected] | Content Wall |
| https://www.ox.security/blog/cve-2025-69443-archon-os-vulnerable-to-unauthenticated-web-to-client-attack/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| coleam00 Archon | >= 0.1.0, <= 0.3.11 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |
Volerion