CVE-2026-5998: A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This m...
Added to the CISA Known Exploited Vulnerabilities catalog on 10 Apr 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 5.3.
A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. Th...
Required action: Review and patch if applicable to your AI infrastructure.