CVE-2026-15628 Details
Description
A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.1.2 is capable of addressing this issue. The patch is named e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. The affected component should be upgraded.
A server-side request forgery (SSRF) vulnerability has been identified in zhayujie ChatGPT-on-WeChat CowAgent versions through 2.1.1. The issue resides in the Vision Tool component, specifically within the Vision._download_to_data_url function of agent/tools/vision/vision.py. The vulnerability allows remote attackers to manipulate image URL inputs, bypassing security checks and potentially accessing internal services or metadata endpoints.
Users can upgrade to zhayujie ChatGPT-on-WeChat CowAgent version 2.1.2, which addresses the vulnerability by adding validation to the Vision tool's image URL handling, blocking requests to internal, loopback, and cloud metadata endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zhayujie/CowAgent/commit/e85290cddcbb5ffc9c235927f4c92e5b4c3ec264 | [email protected] | Source CodeVendor |
| https://github.com/zhayujie/CowAgent/issues/2878 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/zhayujie/CowAgent/pull/2886 | [email protected] | Issue TrackingVendor |
| https://github.com/zhayujie/CowAgent/releases/tag/2.1.2 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-15628 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/855849 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/378130 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/378130/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zhayujie/CowAgent | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion