SQL Injection Vulnerability in iFlytek Astron-Agent Product
CVE-2026-95929

5.3MEDIUM

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
23 September 2026

What is CVE-2026-95929?

A security weakness in the iFlytek astron-agent version up to 1.0.7 has been discovered that allows for SQL injection through the getBotList API endpoint. This vulnerability can be exploited remotely by manipulating the sortDirection argument, potentially compromising the application's database integrity and confidentiality. Users are advised to upgrade to version reward-1575, which includes the necessary patch to eliminate this security risk. Failure to apply this update may leave systems susceptible to malicious attacks.

Affected Version(s)

astron-agent 1.0.0

astron-agent 1.0.1

astron-agent 1.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

T-Chachamaru (VulDB User)
.