飞兔(iFlytek)astron-agent 在 1.1.1 及之前版本中存在一个授权绕过漏洞,该漏洞位于 copyFlow 端点,因为未能验证工作流的所有权关系。经过认证的攻撃者可以枚举工作流标识符,从而覆盖其他租户的工作流,或复制私有工作流以读取其定义。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| iflytek | astron-agent | 0 ~ 1.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet