CPE
iFlytek astron-agent versions through 1.1.1 contain an authorization bypass vulnerability in the copyFlow endpoint, allowing authenticated attackers to access, overwrite, or exfiltrate workflows across tenant boundaries.