Description
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the _select_tools function of the Self-Evolution Review Agent component. Improper authorization logic allows an attacker to manipulate tool selection and gain access to functions that should be restricted, potentially enabling privileged operations. The flaw falls under CWE‑285 and CWE‑863 due to incorrect or missing authorization checks.

Affected Systems

Affected is the zhayujie CowAgent package up to version 2.1.1, as hosted in the official GitHub repository. No other product versions are listed as vulnerable.

Risk and Exploitability

The moderate CVSS score of 5.3 indicates that the vulnerability offers some impact but is not considered critical. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited. Remote exploit is possible, and the exploit code is public, so a determined attacker could remotely manipulate tool selection to bypass authorization.

Generated by OpenCVE AI on August 6, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CowAgent to a patched version that corrects the authorization logic in _select_tools.
  • After updating, audit configuration files and scripts to ensure no unauthorized tool selections are permitted, and remove any legacy tool invocation rules that bypass the new checks.
  • Apply network segmentation or firewall rules to restrict external reachability to the CowAgent service endpoints, limiting exposure to remote attackers.
  • Regularly review CowAgent logs for anomalous tool selection events that may indicate an attempted exploitation.

Generated by OpenCVE AI on August 6, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization
First Time appeared Zhayujie
Zhayujie cowagent
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:zhayujie:cowagent:*:*:*:*:*:*:*:*
Vendors & Products Zhayujie
Zhayujie cowagent
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zhayujie Cowagent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T03:30:10.740Z

Reserved: 2026-08-05T19:04:13.124Z

Link: CVE-2026-18992

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T05:30:16Z

Weaknesses