A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-6129 is a remote authentication bypass vulnerability in zhayujie chatgpt-on-wechat CowAgent versions up to 2.0.4 affecting the Agent Mode Service component. The vulnerability allows unauthenticated remote attackers to manipulate the service, with public exploits already available.
يؤثر هذا الثغرة على خدمة Agent Mode في مكون zhayujie chatgpt-on-wechat CowAgent حتى الإصدار 2.0.4. يسمح بتجاوز المصادقة من خلال معالجة خاصة للطلبات البعيدة، مما يمكن المهاجمين من الوصول غير المصرح به.
A remote authentication bypass vulnerability exists in zhayujie chatgpt-on-wechat CowAgent up to version 2.0.4 in the Agent Mode Service component. Attackers can remotely exploit this vulnerability without authentication, and public exploits are currently available.
Update zhayujie chatgpt-on-wechat CowAgent to a version beyond 2.0.4 immediately. Implement network segmentation to restrict access to the Agent Mode Service. Apply input validation and authentication controls. Monitor for suspicious remote access attempts to the affected component.
قم بتحديث zhayujie chatgpt-on-wechat CowAgent إلى إصدار أحدث من 2.0.4 فوراً. طبق تقسيم الشبكة لتقييد الوصول إلى خدمة Agent Mode. طبق التحقق من صحة المدخلات وضوابط المصادقة. راقب محاولات الوصول البعيد المريبة إلى المكون المتأثر.