VYPR
Vendor

Zhayujie

Products
2
CVEs
12
Across products
13
Status
Private

Products

2

Recent CVEs

12
  • CVE-2026-6126HigApr 12, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-18992MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is…

  • CVE-2026-10214HigJun 1, 2026
    risk 0.41cvss 7.3epss 0.01

    A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched…

  • CVE-2026-6129HigApr 12, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and…

  • CVE-2026-14714MedJul 5, 2026
    risk 0.35cvss 6.5epss 0.00

    A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_token causes missing authentication. The…

  • CVE-2026-5998MedApr 10, 2026
    risk 0.28cvss 5.3epss 0.01

    A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be…

  • CVE-2026-16194MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from…

  • CVE-2026-15628MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in…

  • CVE-2026-15332MedJul 10, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint. The manipulation results in missing authorization. The attack may be launched remotely. The exploit…

  • CVE-2026-15331MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_package of the file agent/skills/service.py of the component Skill Installation Handler. The manipulation of the argument Name leads to path traversal. The attack…

  • CVE-2026-15330HigJul 10, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing a manipulation of the argument image can lead to server-side…

  • CVE-2026-15329MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be…