CVE-2026-14714: A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This ...

Added to the CISA Known Exploited Vulnerabilities catalog on 05 Jul 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.5.

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_token causes missing authentication. The attack may be initiat...

Required action: Review and patch if applicable to your AI infrastructure.