CVE-2026-15628: A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the ...

Added to the CISA Known Exploited Vulnerabilities catalog on 14 Jul 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.3.

A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side reques...

Required action: Review and patch if applicable to your AI infrastructure.