PT-2026-40389 · Archon Os · Archon Os

Published

2026-05-12

·

Updated

2026-05-14

·

CVE-2025-69443

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Archon OS (affected versions not specified)
Description A flaw in the local API handling allows unauthenticated attackers to perform a web-to-client attack. By inducing a user to visit a malicious website, an attacker can bypass Cross-Origin Resource Sharing (CORS)—a security mechanism that restricts resources on a webpage from being requested from another domain—to trigger unauthorized local commands. This can lead to full Remote Code Execution (RCE) and complete system compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-69443

Affected Products

Archon Os