CVE-2026-15330Patch

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing a manipulation of the argument image can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.2 is recommended to address this issue. This patch is called e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. Upgrading the affected component is advised.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-10: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 107-10
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Medium - CowAgent Vision Tool SSRF via image Argument (CVE-2026-15330) CowAgent's Vision Tool (_build_image_content / _download_to_data_url in agent/tools/vision/vision.py) fetches a user-supplied image argument without restricting the destination. An attacker can manipulate the image value to make the server issue requests to arbitrary internal targets - a classic SSRF against internal services and cloud metadata endpoints. The attack is remote and a public PoC is available. VulDB scores it CVSS v4 5.5 / v3.1 7.3 - a moderate-impact SSRF rather than a critical RCE. 👉Upgrade CowAgent to 2.1.2.

    Post summary

    The post announces a moderate‑impact SSRF vulnerability (CVE‑2026‑15330) in CowAgent’s Vision Tool, notes a public PoC exists, and advises upgrading to version 2.1.2 to remediate the issue.

    0000094
    246 followersView on X

Explore more