Zhayujie · Cowagent · CVE-2026-15330
**Name of the Vulnerable Software and Affected Versions**
zhayujie CowAgent versions prior to 2.1.2
**Description**
An issue exists in the Vision Tool component within the ` build image content()` and ` download to data url()` functions of the `agent/tools/vision/vision.py` file. The software fetches a user-supplied `image` argument without restricting the destination, allowing a remote attacker to manipulate this value to induce the server to make requests to arbitrary internal targets, such as internal services and cloud metadata endpoints. This condition leads to server-side request forgery (SSRF), which is a technique used to make a server perform requests to a destination it was not intended to.
**Recommendations**
Upgrade to version 2.1.2.