PT-2026-97147 · Iflytek · Astron-Agent

·

CVE-2026-95930

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions iFlytek astron-agent versions prior to reward-1575
Description A remote attacker can initiate a server-side request forgery (SSRF) by manipulating the endPoint argument within the UrlCheckTool.checkUrl() function of the debugToolV2 API endpoint. Server-side request forgery is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations Upgrade to version reward-1575. As a temporary workaround, restrict access to the debugToolV2 API endpoint to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95930

Affected Products

Astron-Agent