CVE-2026-15331 Details
Description
A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_package of the file agent/skills/service.py of the component Skill Installation Handler. The manipulation of the argument Name leads to path traversal. The attack may be initiated remotely. Upgrading to version 2.1.2 is sufficient to fix this issue. The identifier of the patch is e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. It is advisable to upgrade the affected component.
A path traversal vulnerability has been identified in zhayujie CowAgent versions through 2.1.0. The issue arises in the Skill Installation Handler, specifically within the _add_url and _add_package functions of agent/skills/service.py. The vulnerability allows an authenticated user to manipulate the 'name' argument, causing the application to write files outside the intended 'skills' directory. This could lead to unauthorized overwriting of workspace files and tampering with the agent's persistent state. The vulnerability can be exploited remotely via the cloud management interface.
Upgrade to CowAgent version 2.1.2, which includes a patch for this vulnerability. Instructions for upgrading are available in the CowAgent documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zhayujie/CowAgent/issues/2873 | CISA-ADP | Issue TrackingTechnical DescriptionVendor |
| https://github.com/zhayujie/CowAgent/ | [email protected] | ProductVendor |
| https://github.com/zhayujie/CowAgent/commit/e85290cddcbb5ffc9c235927f4c92e5b4c3ec264 | [email protected] | Source CodeVendor |
| https://github.com/zhayujie/CowAgent/issues/2873 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/zhayujie/CowAgent/pull/2886 | [email protected] | Issue TrackingVendor |
| https://github.com/zhayujie/CowAgent/releases/tag/2.1.2 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-15331 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/853104 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/377274 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/377274/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zhayujie CowAgent | <= 2.1.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion