Description
PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.
Published: 2026-10-10
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server-side request forgery
Action: Immediate Patch
AI Analysis

Impact

PDFMathTranslate (pdf2zh) through version 1.9.11 contains a server‑side request forgery (SSRF) flaw that allows unauthenticated attackers to send arbitrary URLs via the Gradio Web GUI Link input. The translate_file handler passes user‑supplied URLs directly to download_with_limit without validating the scheme or the address, which enables attackers to instruct the server to fetch internal network services and cloud metadata endpoints and retrieve the returned PDF data. This vulnerability can lead to unauthorized disclosure of internal network information and potentially allow attackers to infer sensitive configuration data from cloud metadata. The impact is primarily confidentiality exposure and internal network enumeration rather than direct code execution.

Affected Systems

The affected product is PDFMathTranslate (pdf2zh) for all releases up to version 1.9.11. No other vendors or product variations are listed. Users running the software in any environment where the Gradio Web GUI link input is exposed are susceptible.

Risk and Exploitability

The CVSS score is 6.9, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting that zero‑day exploitation has not yet been observed. The likely attack vector is network‑based, requiring only that the Gradio Web GUI is accessible. An attacker can simply submit a crafted link input and the server will resolve it, potentially revealing internal systems or cloud metadata. The exploit is straightforward and does not require privileged access or complex prerequisites.

Generated by OpenCVE AI on October 10, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PDFMathTranslate to version 1.9.12 or later where the SSRF flaw has been fixed.
  • If an upgrade is not immediately possible, disable or restrict the Gradio Web GUI link input functionality to block unvalidated URL requests.
  • Implement strict validation of URL schemes and host addresses before passing them to download_with_limit to prevent server‑side requests to internal or external resources.

Generated by OpenCVE AI on October 10, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.
Title PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T14:49:39.371Z

Reserved: 2026-10-10T14:39:40.380Z

Link: CVE-2026-108554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T15:16:58.547

Modified: 2026-10-10T15:16:58.547

Link: CVE-2026-108554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T16:30:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)