PT-2026-57078 · Zhayujie · Cowagent
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
zhayujie CowAgent versions prior to 2.1.2
Description
An issue exists in the Vision Tool component within the
build image content() and download to data url() functions of the agent/tools/vision/vision.py file. The software fetches a user-supplied image argument without restricting the destination, allowing a remote attacker to manipulate this value to induce the server to make requests to arbitrary internal targets, such as internal services and cloud metadata endpoints. This condition leads to server-side request forgery (SSRF), which is a technique used to make a server perform requests to a destination it was not intended to.Recommendations
Upgrade to version 2.1.2.
Exploit
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cowagent