iFlytek astron-agent through version 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint. The endpoint fails to validate workflow ownership, allowing authenticated attackers to enumerate workflow identifiers. Attackers can exploit this to overwrite other tenants' workflows or copy private workflows to read their definitions. This is a multi-tenant data isolation failure that enables cross-tenant data access and manipulation. The vulnerability is classified as an Insecure Direct Object Reference (IDOR) type flaw. It affects the WorkflowService.java component in the console backend toolkit. The issue has been reported via GitHub issues and documented by VulnCheck. No patch beyond version 1.1.1 is indicated in the advisory.