Server-Side Request Forgery in iFlytek astron-agent Software
CVE-2026-95930

5.3MEDIUM

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
23 September 2026

What is CVE-2026-95930?

A security vulnerability in the iFlytek astron-agent software, specifically within the debugToolV2 API endpoint, allows for server-side request forgery through manipulation of the endPoint argument in the UrlCheckTool.checkUrl function. This flaw facilitates remote attacks which can lead to compromised server integrity. Users are highly advised to upgrade to version reward-1575 to mitigate the risk associated with this vulnerability.

Affected Version(s)

astron-agent 1.0.0

astron-agent 1.0.1

astron-agent 1.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

T-Chachamaru (VulDB User)
.