Description
A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to trigger a denial of service by manipulating the BrowserTool function in CowAgent's agent/tools/browser/browser_tool.py. The exploitation is remote and the code has been made public, potentially disrupting availability of the affected system.

Affected Systems

CowAgent version 2.1.3 and earlier. The affected component is the Browser Tool located in agent/tools/browser/browser_tool.py.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate threat. EPSS is not available, and it is not listed in the CISA KEV catalog. The attack vector is remote and the exploit is publicly available, raising the likelihood of abuse. The impact is limited to service disruption but can cascade in environments where the tool is part of critical operations.

Generated by OpenCVE AI on September 2, 2026 at 04:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CowAgent to a version higher than 2.1.3 or apply a vendor patch if released.
  • Restrict network access to the BrowserTool endpoint with firewall rules or IP whitelisting to limit exposure.
  • Monitor system logs for abnormal usage patterns or repeated failures of the BrowserTool and configure alerts for potential DoS attempts.
  • If an update is not possible, consider removing or disabling the BrowserTool component until a fix is available and isolate it from external exposure.

Generated by OpenCVE AI on September 2, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service
First Time appeared Zhayujie
Zhayujie cowagent
Weaknesses CWE-404
CPEs cpe:2.3:a:zhayujie:cowagent:*:*:*:*:*:*:*:*
Vendors & Products Zhayujie
Zhayujie cowagent
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zhayujie Cowagent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-02T11:15:15.503Z

Reserved: 2026-09-01T17:56:15.495Z

Link: CVE-2026-84425

cve-icon Vulnrichment

Updated: 2026-09-02T11:15:07.435Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T01:17:23.710

Modified: 2026-09-02T13:55:27.963

Link: CVE-2026-84425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:30:04Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release