CVE-2026-15331

Source
https://cve.org/CVERecord?id=CVE-2026-15331
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15331.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15331
Published
2026-07-10T04:15:10.104Z
Modified
2026-08-12T03:51:13.909557708Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
zhayujie CowAgent Skill Installation service.py _add_package path traversal
Details

A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function addurl/addpackage of the file agent/skills/service.py of the component Skill Installation Handler. The manipulation of the argument Name leads to path traversal. The attack may be initiated remotely. Upgrading to version 2.1.2 is sufficient to fix this issue. The identifier of the patch is e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. It is advisable to upgrade the affected component.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15331.json"
}
References

Affected packages

Git / github.com/zhayujie/cowagent

Affected ranges

Type
GIT
Repo
https://github.com/zhayujie/cowagent
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.0"
        }
    ]
}

Affected versions

2.*
2.0
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15331.json"