Back

MEDIUM

zhayujie CowAgent Skill Installation service.py _add_package path traversal

Published Jul 10, 2026

Description

A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_package of the file agent/skills/service.py of the component Skill Installation Handler. The manipulation of the argument Name leads to path traversal. The attack may be initiated remotely. Upgrading to version 2.1.2 is sufficient to fix this issue. The identifier of the patch is e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. It is advisable to upgrade the affected component.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jul 10, 2026
Updated Jul 10, 2026
Reserved Jul 9, 2026
CISA Vulnrichment
Updated Jul 10, 2026
NVD
Status Deferred
Modified Jul 10, 2026
Red Hat
Severity n/a
Public date n/a