HIGH
iflytek
CVE published 2026-08-29
CVE-2026-82475
The iFlytek astron-agent through version 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint. This vulnerability allows authenticated attackers to enumerate workflow identifiers and potentially overwrite other tenants' workflows or copy private workflows to read their definitions. Users of iFlytek astron-agent should be aware of this vulnerability and take steps to mitigate it, i [truncated]