Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/astron-agent

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-108864 is an authorization bypass vulnerability in iFlytek Astron Agent versions up to 1.1.2. It allows authenticated applications to resume workflows of other applications by supplying their event_id to the resume endpoint. This breaks cross-tenant isolation by enabling attackers to inject resume content and read continuation output streams of victim workflows. The vulnerability has a low CVSS score of 2.3 and affects cloud-hosted services.

Join the discussion

CVE-2026-108263 is a critical vulnerability in iflytek's astron-agent prior to version 1.1.2. It involves improper neutralization of directives in dynamically evaluated code, allowing an authenticated low-privilege tenant to execute arbitrary code as root within the core-workflow container. This can lead to bypassing tenant isolation, unauthorized access to other tenants' data, and disruption of shared services. The issue is fixed in version 1.1.2.

Join the discussion

A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version reward-1575 addresses this issue. The identifier of the patch is 45ee5fb647e9894e73b0d7720fa94a66e4540bbb. The affected component should be upgraded.

Join the discussion
0

A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is possible to launch the attack remotely. Upgrading to version reward-1575 is able to address this issue. This patch is called 6702be70ae802b1048f5fbec91e690e7b71a4165. You should upgrade the affected component.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/astron-agent
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses