SQL Injection Vulnerability in iFlytek Astron-Agent Product
CVE-2026-95929
5.3MEDIUM
What is CVE-2026-95929?
A security weakness in the iFlytek astron-agent version up to 1.0.7 has been discovered that allows for SQL injection through the getBotList API endpoint. This vulnerability can be exploited remotely by manipulating the sortDirection argument, potentially compromising the application's database integrity and confidentiality. Users are advised to upgrade to version reward-1575, which includes the necessary patch to eliminate this security risk. Failure to apply this update may leave systems susceptible to malicious attacks.
Affected Version(s)
astron-agent 1.0.0
astron-agent 1.0.1
astron-agent 1.0.2
