Executive brief
A security vulnerability exists in chatgpt-on-wechat, a tool used to integrate AI chatbots with messaging platforms. An attacker can trick the AI into running unauthorized commands on the underlying server, potentially leading to a full system takeover or data theft. This occurs because the software's built-in safety filters for its command-line tool are easily bypassed.
Technical details
An unauthenticated remote code execution (RCE) vulnerability exists in the Bash Tool component of chatgpt-on-wechat. The vulnerability stems from the '_get_safety_warning' function in 'agent/tools/bash/bash.py', which utilizes a trivial exact-match blocklist to filter dangerous commands. Because the tool passes user-influenced strings directly to 'subprocess.run(shell=True)' without adequate sanitization or sandboxing, an attacker can bypass the filter using slightly altered payloads. This allows for arbitrary OS command execution via the application's unauthenticated '/message' interface. The issue is addressed in version 2.0.9 by binding the web console to localhost by default and improving security controls.
Affected products
- zhayujie chatgpt-on-wechat (CowAgent) up to 2.0.8
Timeline
- 2026-05-07: disclosed: Issue reported on GitHub by YLChen-007
- 2026-05-22: patched: Version 2.0.9 released
- 2026-06-01: advisory: CVE-2026-10214 published
References
- https://github.com/zhayujie/CowAgent/commit/16d9b449c9aa53ccee44144a762a2737d7ba4fc4
- https://github.com/zhayujie/CowAgent/issues/2803
- https://github.com/zhayujie/CowAgent/releases/tag/2.0.9
- https://vuldb.com/cve/CVE-2026-10214
- https://vuldb.com/submit/821929
- https://vuldb.com/vuln/367493
- https://vuldb.com/vuln/367493/cti