CVE-2026-15330 Details
Description
A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing a manipulation of the argument image can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.2 is recommended to address this issue. This patch is called e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. Upgrading the affected component is advised.
A server-side request forgery (SSRF) vulnerability has been identified in zhayujie CowAgent versions through 2.1.1. The issue resides in the Vision Tool component, specifically within the '_build_image_content' and '_download_to_data_url' functions of 'agent/tools/vision/vision.py'. The vulnerability allows remote attackers to manipulate the 'image' argument, causing the server to make unauthorized HTTP requests to internal services or cloud metadata endpoints. This exploitation can be triggered through the Web channel by sending a message that invokes the Vision tool with a crafted image URL.
Users are advised to upgrade to CowAgent version 2.1.2 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zhayujie/CowAgent/ | [email protected] | ProductVendor |
| https://github.com/zhayujie/CowAgent/commit/e85290cddcbb5ffc9c235927f4c92e5b4c3ec264 | [email protected] | Source CodeVendor |
| https://github.com/zhayujie/CowAgent/issues/2872 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/zhayujie/CowAgent/pull/2886 | [email protected] | Issue TrackingVendor |
| https://github.com/zhayujie/CowAgent/releases/tag/2.1.2 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-15330 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/853103 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/377273 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/377273/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zhayujie CowAgent | <= 2.1.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion