Description
A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Bash Tool component of CowAgent up to version 2.1.7, allowing an attacker to trigger a denial of service through manipulations in the bash.py script. The flaw stems from missing validation in an unknown function and is classified as CWE‑404. Remote exploitation leads to the target becoming unresponsive, disrupting its availability and potentially affecting connected services.

Affected Systems

CowAgent, the BASH Tool component released zhayujie, with affected releases up to version 2.1.7.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. However, the publicly disclosed nature and remote attack vector imply that an attacker could initiate repeated execution attempts to exhaust resources and achieve denial of service.

Generated by OpenCVE AI on September 2, 2026 at 03:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CowAgent to a patched or newer version that addresses the bash.py issue once available.
  • Restrict external access to the Bash Tool by firewalling or limiting IP addresses that can reach the affected component.
  • Monitor host logs and network traffic for repeated or abnormal execution attempts to detect potential DoS attacks early.

Generated by OpenCVE AI on September 2, 2026 at 03:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title zhayujie CowAgent Bash Tool bash.py denial of service
First Time appeared Zhayujie
Zhayujie cowagent
Weaknesses CWE-404
CPEs cpe:2.3:a:zhayujie:cowagent:*:*:*:*:*:*:*:*
Vendors & Products Zhayujie
Zhayujie cowagent
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zhayujie Cowagent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-02T00:30:07.139Z

Reserved: 2026-09-01T18:15:51.244Z

Link: CVE-2026-84427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T01:17:23.887

Modified: 2026-09-02T01:17:23.887

Link: CVE-2026-84427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:00:09Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release