Executive brief
CowAgent, an AI assistant and agent framework, contains a security flaw that allows users to execute unauthorized commands on the host system. By sending a specially crafted message through the web chat interface, a user can trigger the agent's built-in bash tool to run shell commands without any approval or authorization check. This could allow an attacker to modify files, access sensitive data, or disrupt the service with the same permissions as the application itself.
Technical details
A missing authorization vulnerability exists in CowAgent up to version 2.1.0 within the Message Endpoint component (specifically channel/channel.py). The application enables agent mode by default and lacks a central runtime approval gate for high-impact tools. When a user sends a message via the 'POST /message' interface, the agent runtime (AgentStreamExecutor) can be influenced to select and execute the built-in 'bash' tool. Because the bash tool only performs minimal safety checks and uses 'subprocess.run' with 'shell=True', an authenticated remote attacker can achieve arbitrary command execution with the privileges of the CowAgent process. As of the advisory date, no patch has been released by the maintainers.
Affected products
- zhayujie CowAgent <= 2.1.0
Timeline
- 2026-07-10: disclosed: Initial publication of the vulnerability details.