Impact
The vulnerability exists in the _select_tools function of the Self-Evolution Review Agent component. Improper authorization logic allows an attacker to manipulate tool selection and gain access to functions that should be restricted, potentially enabling privileged operations. The flaw falls under CWE‑285 and CWE‑863 due to incorrect or missing authorization checks.
Affected Systems
Affected is the zhayujie CowAgent package up to version 2.1.1, as hosted in the official GitHub repository. No other product versions are listed as vulnerable.
Risk and Exploitability
The moderate CVSS score of 5.3 indicates that the vulnerability offers some impact but is not considered critical. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited. Remote exploit is possible, and the exploit code is public, so a determined attacker could remotely manipulate tool selection to bypass authorization.
OpenCVE Enrichment