{"data":{"id":"1b62b3b8-bfd1-4f3c-8574-b72e4d1e7cd0","title":"CVE-2026-5998: A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the…","summary":"A path traversal flaw, CVE-2026-5998, affects zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. It sits in the function dispatch of agent/memory/service.py, reached through the API Memory Content Endpoint by manipulating the filename argument. The attack can be launched remotely, and a published exploit exists.","solution":"Upgrading to version 2.0.5 mitigates this issue. Patch name: 174ee0cafc9e8e9d97a23c305418251485b8aa89. It is recommended to upgrade the affected component.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5998","publishedAt":"2026-04-10T02:16:04.460Z","cveId":"CVE-2026-5998","cweIds":["CWE-22"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["CowAgent","chatgpt-on-wechat"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"zhayujie chatgpt-on-wechat CowAgent path traversal in Memory API","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00697,"epssCheckedAt":"2026-10-10T03:00:37.847Z","kevDateAdded":null,"advisoryAliases":["GHSA-m63g-rhjw-f2v6"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:49:34.931Z","patchAvailable":null,"disclosureDate":"2026-04-10T02:16:04.460Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}