Impact
iFlytek astron‑agent through version 1.1.1 contains an authorization bypass in the copyFlow endpoint. The endpoint does not verify that the authenticated user owns the workflow they are copying. As a result, a user can enumerate workflow identifiers, copy private workflows from other tenants, or overwrite workflow definitions belonging to other tenants, effectively allowing unauthorized modification and disclosure of confidential workflow configurations. The flaw is a classic example of CWE‑862: Missing Authorization.
Affected Systems
The affected product is iFlytek astron‑agent version 1.1.1 and earlier. Vulnerability applies to all deployments of that product that use the default copyFlow function. No specific environment constraints are listed; the issue relies on authenticated access to the API.
Risk and Exploitability
The vulnerability has a CVSS score of 8.6 indicating high severity. EPSS is not provided, so the current exploitation probability cannot be quantified, but the flaw requires only authenticated users, which many tenants will have. Because the attacker can impersonate other tenants' workflows, the risk is significant for multi‑tenant installations. The flaw is not currently listed in the CISA KEV catalog, but that does not reduce its potential impact.
OpenCVE Enrichment