CVE-2026-95930
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-918
Falsificación de solicitud en servidor (SSRF)
Fecha de publicación:
23/09/2026
Última modificación:
23/09/2026
Descripción
*** Pendiente de traducción *** A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version reward-1575 addresses this issue. The identifier of the patch is 45ee5fb647e9894e73b0d7720fa94a66e4540bbb. The affected component should be upgraded.
Impacto
Puntuación base 4.0
5.30
Gravedad 4.0
MEDIA
Puntuación base 3.x
6.30
Gravedad 3.x
MEDIA
Puntuación base 2.0
6.50
Gravedad 2.0
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/iflytek/astron-agent/
- https://github.com/iflytek/astron-agent/commit/45ee5fb647e9894e73b0d7720fa94a66e4540bbb
- https://github.com/iflytek/astron-agent/issues/1323
- https://github.com/iflytek/astron-agent/pull/1338
- https://github.com/iflytek/astron-agent/releases/tag/reward-1575
- https://vuldb.com/cve/CVE-2026-95930
- https://vuldb.com/submit/953331
- https://vuldb.com/vuln/408552
- https://vuldb.com/vuln/408552/cti
- https://github.com/iflytek/astron-agent/issues/1323


