Impact
The vulnerability is a server‑side request forgery that occurs when an attacker supplies a crafted image argument to the Vision._download_to_data_url function in the Vision Tool. The attacker can cause the server to make requests to arbitrary external systems. Based on the description, it is inferred that this could allow interaction with other services or internal resources. The flaw can be triggered remotely and a public exploit has been released, meaning an attacker only needs to send a crafted request to the vulnerable endpoint to leverage this weakness.
Affected Systems
The affected product is the open‑source chatgpt‑on‑wechat CowAgent released by zhayujie. Versions up to and including 2.1.1 are affected; the official patch in 2.1.2 resolves the SSRF flaw.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range, and the exploit can be launched from any remote host as the exploit requires no privileged authentication. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The CVE is not listed in the KEV catalog. Based on the description, it is inferred that the SSRF capability could be a concern for systems that accept untrusted input or are exposed to the internet.
OpenCVE Enrichment