Retour à la veille

CVE-2026-108864

Publié : 11 octobre 2026
Modifié : 11 octobre 2026
Lien officiel NVD
Score CVSS
4.2
MEDIUM

Description détaillée

iFlytek Astron Agent through 1.1.2 contains an insecure direct object reference vulnerability that allows authenticated applications to resume other applications' paused workflows by supplying their event_id to POST /workflow/v1/resume. Attackers can predict Snowflake event IDs to inject resume content into victim workflows and read their continuation output stream, breaking cross-tenant isolation.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Références et Patchs