Vulnerability  ·  2026-10-11

AstronRPA (iFlytek) OpenResty gateway accepts any Bearer token → unauthenticated AI-service access and user impersonation (CVSS 7.3)

VulnerabilityHigh impactGlobalCVE-2026-108548
Verified via NVD REST API (published 2026-10-10, VulnCheck; CVSS 7.3): the gateway accepts any Bearer token and passes an arbitrary X-User-Id to the AI service. This pairs with the previously-reported AstronRPA smart-component chat XSS (CVE-2026-108159) to give a full unauthenticated-to-code-execution chain on the same platform.
AstronRPA is an AI-driven RPA product whose whole purpose is letting AI act on connected systems; an unauthenticated auth-bypass that lets anyone impersonate any user on its AI service routes is a direct compromise of the agent's authorization boundary.
The OpenResty gateway's auth_handler.lua accepts any Bearer token without validation, so unauthenticated attackers send an arbitrary Bearer value to reach protected /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id/user_id headers to impersonate any user (CWE-287).
iflytek/astron-rpa <= 1.1.6 (OpenResty auth_handler.lua; FastAPI dependencies)
No fixed release observed in the advisory; restrict the gateway to validate tokens against the AI service, drop Nginx-level trust of X-User-Id, and place the platform behind authenticated network controls until patched. See advisory PT-2026-109663 / VulnCheck.
NVD CVE-2026-108548NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →