CVE-2026-95930: iFlytek astron-agent debugToolV2 API endpoint UrlCheckTool.checkUrl server-side request forgery
A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version reward-1575 addresses this issue. The identifier of the patch is 45ee5fb647e9894e73b0d7720fa94a66e4540bbb. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iFlytek astron-agentto a version that resolves this vulnerability.Fixed in reward-1575Patch 45ee5fb647e9894e73b0d7720fa94a66e4540bbb
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be initiated remotely, but the CVSS vector indicates that low-level privileges are required. No user interaction is required.
Which deployments are affected?
iFlytek astron-agent versions up to 1.0.6 are affected, specifically where the debugToolV2 API endpoint exposes UrlCheckTool.checkUrl. The vulnerable input is the endPoint argument.
What is the recommended remediation?
Upgrade the affected component to version reward-1575. The referenced patch identifier is 45ee5fb647e9894e73b0d7720fa94a66e4540bbb.