{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/iflytek/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:iflytek:astron-agent:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-82475"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["astron-agent (\u003c= 1.1.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["iFlytek"],"content_html":"\u003cp\u003eiFlytek astron-agent versions through 1.1.1 are susceptible to an authorization bypass vulnerability located within the copyFlow endpoint. The vulnerability stems from a failure to perform adequate ownership validation when processing requests to copy or manipulate workflow data. Because the application does not verify if the authenticated user has appropriate permissions for the requested workflow identifier, an attacker can enumerate valid workflow IDs and perform unauthorized actions. This flaw impacts multi-tenant environments by permitting attackers to overwrite the workflows of other tenants or exfiltrate private workflow definitions. Defenders should prioritize patching, as this vulnerability allows for data exfiltration and integrity compromise within the agent platform.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the confidentiality and integrity of automated workflows managed within astron-agent. If exploited, an attacker can read sensitive workflow logic and configuration (exfiltration) or modify existing processes (integrity compromise), potentially leading to further unauthorized operations within the affected tenant environment. The scope of targeting includes any multi-tenant deployment where tenant isolation is expected but not enforced at the application layer.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch all deployments of astron-agent to a version later than 1.1.1 immediately, as remediation for CVE-2026-82475 is required to enforce proper ownership checks.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and authorization logging at the API gateway layer to detect excessive attempts to access the /copyFlow endpoint from non-authorized user contexts.\u003c/li\u003e\n\u003cli\u003eReview access logs for the copyFlow endpoint to identify potential workflow enumeration activity, characterized by high-frequency requests targeting different workflow identifiers from a single user session.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-29T17:41:30Z","date_published":"2026-08-29T17:41:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-astron-agent-auth-bypass/","summary":"iFlytek astron-agent versions through 1.1.1 contain an authorization bypass vulnerability in the copyFlow endpoint, allowing authenticated attackers to access, overwrite, or exfiltrate workflows across tenant boundaries.","title":"Authorization Bypass in iFlytek astron-agent","url":"https://feed.craftedsignal.io/briefs/2026-08-astron-agent-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - IFlytek","version":"https://jsonfeed.org/version/1.1"}