What happened
VulnCheck published CVE-2026-108864 (published 2026-10-11, CVSS 4.2, CWE-639) for iFlytek Astron Agent ≤ 1.1.2: the workflow resume endpoint lacks ownership checks, so another application can resume and inject content into a victim's paused AI workflows and read their output. Verified against NVD REST API.
Why it matters
A cross-tenant isolation break in an agent workflow engine: attacker-controlled continuation input can steer a victim's workflow mid-execution. Low CVSS and reliance on predictable event IDs keep it at precision-tier C, but it is a genuine agent-workflow integrity issue.
Attack vector
An authenticated application sends POST /workflow/v1/resume with a victim's predictable Snowflake event_id (CWE-639), causing the victim's paused workflow to resume with attacker-supplied content and exposing its continuation output stream.
Affected systems
iFlytek Astron Agent through 1.1.2
Mitigation
Upgrade past 1.1.2; consider non-predictable event IDs and per-application ownership checks. Advisory: https://www.vulncheck.com/advisories/iflytek-astron-agent-through-1.1.2-authorization-bypass-via-workflow-v1-resume-endpoint