Unrated severityNVD Advisory· Published Aug 6, 2026
zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization
CVE-2026-18992
Description
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/zhayujie/CowAgent/issues/2904mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-18992mitrethird-party-advisory
- vuldb.com/submit/862609mitrethird-party-advisory
- github.com/zhayujie/CowAgent/issues/2904mitreissue-tracking
- vuldb.com/vuln/386368mitrevdb-entrytechnical-description
- vuldb.com/vuln/386368/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.