漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization
Vulnerability Description
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
授权机制不正确
Vulnerability Title
zhayujie CowAgent 授权问题漏洞
Vulnerability Description
zhayujie CowAgent是zhayujie个人开发者开源的一个基于大模型的智能助理与可扩展Agent框架。 zhayujie CowAgent 2.1.1及之前版本存在授权问题漏洞,该漏洞源于Self-Evolution Review Agent组件中agent/evolution/executor.py文件的_select_tools函数存在错误操作,可能导致不正确的授权。
CVSS Information
N/A
Vulnerability Type
N/A