PT-2026-55769 · Zhayujie · Chatgpt-On-Wechat Cowagent
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
zhayujie chatgpt-on-wechat CowAgent version 2.1.0
Description
A remote authentication bypass exists in the
wx Endpoint. The issue resides in the verify server() function within the channel/wechatmp/common.py file. Manipulation of the wechatmp token argument allows an attacker to bypass authentication because the system previously relied on a signature check that would degenerate into a predictable hash if the token was missing or empty. This allows unauthorized access via the '/wx' endpoint.Recommendations
Upgrade to version 2.1.1.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chatgpt-On-Wechat Cowagent