CVE-2026-95929
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-74
Neutralización incorrecta de elementos especiales en la salida utilizada por un componente interno (Inyección)
Fecha de publicación:
23/09/2026
Última modificación:
26/09/2026
Descripción
*** Pendiente de traducción *** A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is possible to launch the attack remotely. Upgrading to version reward-1575 is able to address this issue. This patch is called 6702be70ae802b1048f5fbec91e690e7b71a4165. You should upgrade the affected component.
Impacto
Puntuación base 4.0
5.30
Gravedad 4.0
MEDIA
Puntuación base 3.x
6.30
Gravedad 3.x
MEDIA
Puntuación base 2.0
6.50
Gravedad 2.0
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/iflytek/astron-agent/
- https://github.com/iflytek/astron-agent/commit/6702be70ae802b1048f5fbec91e690e7b71a4165
- https://github.com/iflytek/astron-agent/issues/1329
- https://github.com/iflytek/astron-agent/pull/1342
- https://github.com/iflytek/astron-agent/releases/tag/reward-1575
- https://vuldb.com/cve/CVE-2026-95929
- https://vuldb.com/submit/953330
- https://vuldb.com/vuln/408551
- https://vuldb.com/vuln/408551/cti


