Impact
A flaw in the BrowserTool._do_navigate method of CowAgent allows an attacker to read sensitive data. The vulnerability is identified as CWE-200 and CWE-284, potentially exposing internal state or configuration information. The description notes that manipulation triggers a data disclosure, and an exploit is publicly available.
Affected Systems
The affected product is zhayujie:CowAgent up to version 2.1.0. Users running 2.1.0 or earlier should be aware of the vulnerability. No later versions are noted as mitigated.
Risk and Exploitability
The CVSS score of 5.3 represents moderate risk. The EPSS score is less than 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. However, the exploit is publicly disclosed and can be initiated remotely, raising the practical likelihood of exploitation. Authentication requirements are not explicitly stated in the CVE description, so the security context of the vulnerable method remains uncertain.
OpenCVE Enrichment