
🚨Medium - CowAgent Vision Tool SSRF via image Argument (CVE-2026-15330) CowAgent's Vision Tool (_build_image_content / _download_to_data_url in agent/tools/vision/vision.py) fetches a user-supplied image argument without restricting the destination. An attacker can manipulate the image value to make the server issue requests to arbitrary internal targets - a classic SSRF against internal services and cloud metadata endpoints. The attack is remote and a public PoC is available. VulDB scores it CVSS v4 5.5 / v3.1 7.3 - a moderate-impact SSRF rather than a critical RCE. 👉Upgrade CowAgent to 2.1.2.
Post summary
The post announces a moderate‑impact SSRF vulnerability (CVE‑2026‑15330) in CowAgent’s Vision Tool, notes a public PoC exists, and advises upgrading to version 2.1.2 to remediate the issue.
