PT-2026-57957 · Zhayujie+1 · Chatgpt-On-Wechat Cowagent+1
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
zhayujie chatgpt-on-wechat CowAgent versions prior to 2.1.2
Description
A server-side request forgery (SSRF) exists in the Vision Tool component. This occurs when the
image argument is manipulated within the Vision. download to data url() function located in the agent/tools/vision/vision.py file. This flaw allows a remote attacker to initiate unauthorized requests from the server.Recommendations
Update to version 2.1.2.
As a temporary mitigation, restrict access to the
Vision. download to data url() function.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chatgpt-On-Wechat Cowagent
Cowagent