Server-Side Request Forgery in iFlytek astron-agent Software
CVE-2026-95930
5.3MEDIUM
What is CVE-2026-95930?
A security vulnerability in the iFlytek astron-agent software, specifically within the debugToolV2 API endpoint, allows for server-side request forgery through manipulation of the endPoint argument in the UrlCheckTool.checkUrl function. This flaw facilitates remote attacks which can lead to compromised server integrity. Users are highly advised to upgrade to version reward-1575 to mitigate the risk associated with this vulnerability.
Affected Version(s)
astron-agent 1.0.0
astron-agent 1.0.1
astron-agent 1.0.2
