PT-2026-97146 · Iflytek · Astron-Agent

·

CVE-2026-95929

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions iFlytek astron-agent versions prior to reward-1575
Description A SQL injection flaw exists in the getBotList API endpoint within the console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml file. A remote attacker can exploit this by manipulating the sortDirection argument, allowing for the execution of unauthorized SQL commands.
Recommendations Upgrade to version reward-1575. As a temporary mitigation, avoid using the sortDirection argument in the getBotList API endpoint.

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95929

Affected Products

Astron-Agent