CVE-2026-84427: zhayujie CowAgent Bash Tool bash.py denial of service
A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely, but the vector indicates that the attacker needs low-level privileges. No user interaction is required.
What versions are affected?
CowAgent versions up to and including 2.1.7 are identified as affected, specifically the Bash Tool component and its agent/tools/bash/bash.py file.
What is the operational impact?
Successful exploitation can cause a denial of service. The provided information does not indicate confidentiality or integrity impact.
Is exploit code available?
The exploit has been publicly disclosed and may be used. The vendor was contacted but did not provide a response.