Insecure Direct Object Reference in iFlytek Astron Agent affecting multiple workflows
CVE-2026-108864
2.3LOW
What is CVE-2026-108864?
The iFlytek Astron Agent, up to version 1.1.2, is susceptible to an insecure direct object reference vulnerability that enables authenticated users to resume paused workflows of other applications. By merely providing an event_id via a POST request to /workflow/v1/resume, attackers could exploit predictable Snowflake event IDs to manipulate ongoing workflows and extract output streams from unauthorized entities, jeopardizing the integrity of cross-tenant isolation.
Affected Version(s)
astron-agent 0 <= 1.1.2
