Impact
The vulnerability allows an attacker to trigger a denial of service by manipulating the BrowserTool function in CowAgent's agent/tools/browser/browser_tool.py. The exploitation is remote and the code has been made public, potentially disrupting availability of the affected system.
Affected Systems
CowAgent version 2.1.3 and earlier. The affected component is the Browser Tool located in agent/tools/browser/browser_tool.py.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate threat. EPSS is not available, and it is not listed in the CISA KEV catalog. The attack vector is remote and the exploit is publicly available, raising the likelihood of abuse. The impact is limited to service disruption but can cascade in environments where the tool is part of critical operations.
OpenCVE Enrichment