PT-2026-57078 · Zhayujie · Cowagent

·

CVE-2026-15330

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zhayujie CowAgent versions prior to 2.1.2
Description An issue exists in the Vision Tool component within the build image content() and download to data url() functions of the agent/tools/vision/vision.py file. The software fetches a user-supplied image argument without restricting the destination, allowing a remote attacker to manipulate this value to induce the server to make requests to arbitrary internal targets, such as internal services and cloud metadata endpoints. This condition leads to server-side request forgery (SSRF), which is a technique used to make a server perform requests to a destination it was not intended to.
Recommendations Upgrade to version 2.1.2.

Exploit

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15330

Affected Products

Cowagent