Junglewise Threat Intelligence

CVE-2026-5998: zhayujie CowAgent path traversal in Memory Content API

CVE-2026-5998 · Severity: medium · CVSS 5.3 · Published 2026-04-10

Vendors: Zhayujie.

Executive brief

A security vulnerability exists in CowAgent, a tool used to integrate ChatGPT with WeChat. An attacker can remotely access sensitive files on the server where the software is running, such as system passwords, private SSH keys, and unmasked API keys for AI services. This could lead to a complete compromise of the server and unauthorized use of expensive AI service accounts.

Technical details

A path traversal vulnerability (CWE-22) exists in the `/api/memory/content` endpoint of CowAgent. The `filename` parameter is passed to the `_resolve_path` function in `agent/memory/service.py`, which uses `os.path.join()` without validating that the resulting path remains within the intended directory. By supplying directory traversal sequences (e.g., `../../`), an unauthenticated remote attacker can escape the application's workspace to read sensitive files like `/etc/passwd`, `config.json` (containing full API keys), or SSH private keys. The issue is fixed in version 2.0.5 by implementing proper path sanitization.

Affected products

  • zhayujie CowAgent (chatgpt-on-wechat) up to 2.0.4

Timeline

  • 2026-04-09: disclosed: Vulnerability reported via GitHub Issues
  • 2026-04-09: patched: Fix committed to repository
  • 2026-04-10: advisory: CVE-2026-5998 published

References