zhayujie CowAgent Server-Side Request Forgery Vulnerability in Vision Tool

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in zhayujie CowAgent versions through 2.1.1. The issue resides in the Vision Tool component, specifically within the '_build_image_content' and '_download_to_data_url' functions of 'agent/tools/vision/vision.py'. The vulnerability allows remote attackers to manipulate the 'image' argument, causing the server to make unauthorized HTTP requests to internal services or cloud metadata endpoints. This exploitation can be triggered through the Web channel by sending a message that invokes the Vision tool with a crafted image URL.

Impact

Exploitation of this vulnerability allows for server-side request forgery, where an attacker can make the server fetch remote resources and potentially access internal services or metadata endpoints.

Reproduction

The vulnerability can be reproduced by sending a message through the Web console that includes a URL pointing to an image hosted on a loopback or private network address. This will trigger the Vision tool to fetch the image URL server-side, without any validation, effectively exploiting the SSRF vulnerability.

Remediation

Users are advised to upgrade to CowAgent version 2.1.2 or later, where this vulnerability has been patched.

Added: Jul 10, 2026, 5:32 AM
Updated: Jul 10, 2026, 5:32 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.