Impact
PDFMathTranslate (pdf2zh) through version 1.9.11 contains a server‑side request forgery (SSRF) flaw that allows unauthenticated attackers to send arbitrary URLs via the Gradio Web GUI Link input. The translate_file handler passes user‑supplied URLs directly to download_with_limit without validating the scheme or the address, which enables attackers to instruct the server to fetch internal network services and cloud metadata endpoints and retrieve the returned PDF data. This vulnerability can lead to unauthorized disclosure of internal network information and potentially allow attackers to infer sensitive configuration data from cloud metadata. The impact is primarily confidentiality exposure and internal network enumeration rather than direct code execution.
Affected Systems
The affected product is PDFMathTranslate (pdf2zh) for all releases up to version 1.9.11. No other vendors or product variations are listed. Users running the software in any environment where the Gradio Web GUI link input is exposed are susceptible.
Risk and Exploitability
The CVSS score is 6.9, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting that zero‑day exploitation has not yet been observed. The likely attack vector is network‑based, requiring only that the Gradio Web GUI is accessible. An attacker can simply submit a crafted link input and the server will resolve it, potentially revealing internal systems or cloud metadata. The exploit is straightforward and does not require privileged access or complex prerequisites.
OpenCVE Enrichment