MediumVulnerabilityLLM-specific
CVE-2026-5998: zhayujie chatgpt-on-wechat CowAgent path traversal in Memory API
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-5998
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.7%
Summary
A path traversal flaw, CVE-2026-5998, affects zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. It sits in the function dispatch of agent/memory/service.py, reached through the API Memory Content Endpoint by manipulating the filename argument. The attack can be launched remotely, and a published exploit exists.
Mitigation
Upgrading to version 2.0.5 mitigates this issue. Patch name: 174ee0cafc9e8e9d97a23c305418251485b8aa89. It is recommended to upgrade the affected component.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database