Authorization Bypass Vulnerability in iFlytek astron-agent
CVE-2026-82475
8.6HIGH
What is CVE-2026-82475?
The iFlytek astron-agent, versions up to 1.1.1, is susceptible to an authorization bypass vulnerability in its copyFlow endpoint. This flaw stems from improper validation of workflow ownership, allowing authenticated attackers to enumerate workflow identifiers. As a result, they can overwrite the workflows of other tenants or copy private workflows, gaining access to their definitions and sensitive information inherent within.
Affected Version(s)
astron-agent 0 <= 1.1.1
