๐Ÿ” CVE Alert

CVE-2026-5998

MEDIUM 5.3

zhayujie chatgpt-on-wechat CowAgent API Memory Content Endpoint service.py dispatch path traversal

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
15th

A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.0.5 mitigates this issue. Patch name: 174ee0cafc9e8e9d97a23c305418251485b8aa89. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CWE CWE-22
Vendor zhayujie
Product chatgpt-on-wechat cowagent
Published Apr 10, 2026
Last Updated Apr 10, 2026
Stay Ahead of the Next One

Get instant alerts for zhayujie chatgpt-on-wechat cowagent

Be the first to know when new medium vulnerabilities affecting zhayujie chatgpt-on-wechat cowagent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

zhayujie / chatgpt-on-wechat CowAgent
2.0.0 2.0.1 2.0.2 2.0.3 2.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/356552 vuldb.com: https://vuldb.com/vuln/356552/cti vuldb.com: https://vuldb.com/submit/793558 github.com: https://github.com/zhayujie/chatgpt-on-wechat/issues/2734 github.com: https://github.com/zhayujie/chatgpt-on-wechat/issues/2734#issue-4178013778 github.com: https://github.com/zhayujie/chatgpt-on-wechat/commit/174ee0cafc9e8e9d97a23c305418251485b8aa89 github.com: https://github.com/zhayujie/chatgpt-on-wechat/releases/tag/2.0.5

Credits

๐Ÿ” Yu_Bao (VulDB User) VulDB CNA Team