VYPR

Cowagent

by Zhayujie

Source repositories

CVEs (11)

  • CVE-2026-18992MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is…

  • CVE-2026-10214HigJun 1, 2026
    risk 0.41cvss 7.3epss 0.01

    A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched…

  • CVE-2026-14714MedJul 5, 2026
    risk 0.35cvss 6.5epss 0.01

    A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_token causes missing authentication. The…

  • CVE-2026-84427MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been…

  • CVE-2026-84425MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The…

  • CVE-2026-16194MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from…

  • CVE-2026-15628MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in…

  • CVE-2026-15332MedJul 10, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint. The manipulation results in missing authorization. The attack may be launched remotely. The exploit…

  • CVE-2026-15331MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.01

    A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_package of the file agent/skills/service.py of the component Skill Installation Handler. The manipulation of the argument Name leads to path traversal. The attack…

  • CVE-2026-15330HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing a manipulation of the argument image can lead to server-side…

  • CVE-2026-15329MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be…