Skip to content
MediumVulnerabilityLLM-specific

CVE-2026-5998: zhayujie chatgpt-on-wechat CowAgent path traversal in Memory API

Identifier
CVE-2026-5998
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

A path traversal flaw, CVE-2026-5998, affects zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. It sits in the function dispatch of agent/memory/service.py, reached through the API Memory Content Endpoint by manipulating the filename argument. The attack can be launched remotely, and a published exploit exists.

Mitigation

Upgrading to version 2.0.5 mitigates this issue. Patch name: 174ee0cafc9e8e9d97a23c305418251485b8aa89. It is recommended to upgrade the affected component.