PatchSiren cyber security CVE debrief
CVE-2026-95929 iFlytek CVE debrief
A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is possible to launch the attack remotely. Upgrading to version reward-1575 is able to address this issue. This patch is called 6702be70ae802b1048f5fbec91e690e7b71a4165.
- Vendor
- iFlytek
- Product
- astron-agent
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for iFlytek astron-agent deployments should assess exposure and prioritize upgrading to version reward-1575 or later to address the SQL injection vulnerability.
Why it matters
CVE-2026-95929 is a SQL injection vulnerability in the getBotList API endpoint of iFlytek astron-agent. Defenders should assess exposure, prioritize upgrading to version reward-1575 or later, and implement additional security measures to prevent SQL injection attacks.
- Verify and upgrade affected iFlytek astron-agent deployments to prevent SQL injection attacks
- Monitor API endpoint usage for suspicious activity
- Implement additional security measures to prevent SQL injection attacks
Technical summary
The vulnerability is located in the console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml file of the iFlytek astron-agent component, specifically in the getBotList API endpoint. The sortDirection argument can be manipulated to inject malicious SQL code, allowing for remote attacks. The affected component is iFlytek astron-agent up to version 1.0.7. Upgrading to version reward-1575 is able to address this issue. This patch is called 6702be70ae802b1048f5fbec91e690e7b71a4165. The CVE record and NVD entry provide details about the vulnerability.
Defensive priority
Upgrade to version reward-1575 or later to address the SQL injection vulnerability in the getBotList API endpoint of iFlytek astron-agent.
Recommended defensive actions
- Upgrade to version reward-1575 or later
- Review and monitor API endpoint usage
- Implement additional security measures to prevent SQL injection attacks
- Verify affected iFlytek astron-agent deployments exist
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, including its description, affected component, and available patch. The iFlytek astron-agent component is affected up to version 1.0.7. The vulnerability is located in the console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml file. The sortDirection argument can be manipulated to inject malicious SQL code, allowing for remote attacks. There is no indication of publicly available exploits or reports of attacks in the wild. The patch 6702be70ae802b
Sources and references
Verified primary and authoritative sources
-
CVE-2026-95929 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-95929
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-95929 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95929
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent/
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent/commit/6702be70ae802b1048f5fbec91e690e7b71a4165
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent/issues/1329
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent/pull/1342
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent/releases/tag/reward-1575
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-95929
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/953330
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408551
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.