top of page
perceptive_background_267k.jpg

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authentica…

Published:

29 August 2026 at 00:00:00

Alert date:

29 August 2026 at 20:03:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Identity & Access, Web Technologies

iFlytek astron-agent through version 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint. The endpoint fails to validate workflow ownership, allowing authenticated attackers to enumerate workflow identifiers. Attackers can exploit this to overwrite other tenants' workflows or copy private workflows to read their definitions. This is a multi-tenant data isolation failure that enables cross-tenant data access and manipulation. The vulnerability is classified as an Insecure Direct Object Reference (IDOR) type flaw. It affects the WorkflowService.java component in the console backend toolkit. The issue has been reported via GitHub issues and documented by VulnCheck. No patch beyond version 1.1.1 is indicated in the advisory.

Technical details

Mitigation steps:

Affected products:

iFlytek astron-agent 1.1.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page