CVE-2026-18992

Summary

A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Affected Software

VendorProductVersion RangeStatus
zhayujieCowAgent2.1.0affected
zhayujieCowAgent2.1.1affected

Weaknesses

  • CWE-863: Incorrect Authorization
  • CWE-285: Improper Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References