Impact
The vulnerability in zhayujie CowAgent allows manipulation of a channel function within the Message Endpoint module, resulting in a missing authorization check. This flaw permits an attacker to attempt unauthorized actions on the endpoint, potentially reading, modifying, or deleting messages that should be protected. The impact is unauthorized access, as indicated by CWE‑862 (Missing Authorization) and CWE‑863 (Missing Access Control).
Affected Systems
All instances of zhayujie CowAgent version 2.1.0 or earlier are affected. The attack vector is through the Message Endpoint component in the channel.py file. Administrators should confirm the version in use and note that the vendor has not yet released a fix as of the current data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. An EPSS score of <1% signals a low but non‑zero likelihood of exploitation. Because the exploit has been released publicly, a remote attacker could target vulnerable instances. The vulnerability is not listed in CISA’s KEV catalog. The missing authorization check does not require local compromise, allowing remote manipulation of the messaging interface.
OpenCVE Enrichment