๐Ÿ” CVE Alert

CVE-2026-18992

MEDIUM 6.3

zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CWE CWE-863 CWE-285
Vendor zhayujie
Product cowagent
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for zhayujie cowagent

Be the first to know when new medium vulnerabilities affecting zhayujie cowagent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

zhayujie / CowAgent
2.1.0 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/386368 vuldb.com: https://vuldb.com/vuln/386368/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18992 vuldb.com: https://vuldb.com/submit/862609 github.com: https://github.com/zhayujie/CowAgent/issues/2904 github.com: https://github.com/zhayujie/CowAgent/issues/2904#issuecomment-4756833239 github.com: https://github.com/zhayujie/CowAgent/

Credits

๐Ÿ” ChenMarry (VulDB User)