CVE-2026-84425: zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service
A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browsertool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which installations should be considered affected?
The affected scope is zhayujie CowAgent up to version 2.1.3, specifically the Browser Tool component's BrowserTool function in agent/tools/browser/browser_tool.py.
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires low privileges. The CVSS vector indicates network access, low attack complexity, and no user interaction requirement.
Is public exploit information available?
Yes. The exploit has been made public and could be used.