PT-2026-32186 · Zhayujie · Chatgpt-On-Wechat Cowagent

York Shen

·

Published

2026-04-12

·

Updated

2026-04-13

·

CVE-2026-6129

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zhatujie chatgpt-on-wechat CowAgent versions up to 2.0.4
Description A flaw exists in the Agent Mode Service component of zhayujie chatgpt-on-wechat CowAgent up to version 2.0.4, allowing for missing authentication. This issue can be exploited remotely through a manipulation. The exploit is publicly available. The project was notified of the issue but has not yet responded.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-6129

Affected Products

Chatgpt-On-Wechat Cowagent