Junglewise Threat Intelligence

CVE-2026-95930: iFlytek astron-agent SSRF in debug tool endpoint

CVE-2026-95930 · Severity: medium · CVSS 6.3 · Published 2026-09-23

Technologies: iFlytek Astron-Agent. Vendors: iFlytek.

Executive brief

iFlytek astron-agent is an enterprise agentic workflow platform. A server-side request forgery (SSRF) vulnerability in the debugToolV2 API endpoint allows remote attackers to manipulate the endPoint parameter and force the server to make arbitrary HTTP requests to internal or external systems, potentially exposing sensitive internal services or data.

Technical details

The UrlCheckTool.checkUrl function in the debugToolV2 API endpoint is vulnerable to SSRF via unsafe handling of the endPoint parameter. The vulnerability requires network access but no authentication or user interaction. An attacker can exploit this to bypass URL validation and redirect filtering, accessing internal services or making requests to attacker-controlled servers. The patch implements bounded redirect chain validation and improved blacklist/whitelist checks on each hop.

Affected products

  • iFlytek astron-agent up to 1.0.6

Timeline

  • 2026-09-23: disclosed
  • 2026-05-18: patched: Commit 45ee5fb647e9894e73b0d7720fa94a66e4540bbb

References

Related threats