Description
A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the component pdf-tools-mcp. Performing a manipulation of the argument pdf_file_path results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch ASAP
AI Analysis

Impact

The vulnerability resides in the ControlFlowNode function of the pdf-tools-mcp component inside cowork_bench. By manipulating the pdf_file_path argument, an attacker can cause the server to request arbitrary URLs, leading to server‑side request forgery (SSRF). This flaw does not require authentication and can be triggered remotely. An exploit has already been published, and the product uses a rolling release model, so no specific fixed revision has been made public yet.

Affected Systems

The affected product is 0717376 cowork_bench. No specific version information is available because the project provides continuous delivery via rolling releases. The vulnerability is present in the code base up to commit d943e75bc0fc8e3b27141979300cd8cbcd1e890d.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability is considered moderate. The EPSS score is not available, but the public nature of the exploit and the lack of a patch suggest a realistic threat. The flaw is listed as a server‑side request forgery (CWE‑918).

Generated by OpenCVE AI on September 20, 2026 at 21:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the most recent release of cowork_bench from the official repository.
  • If an update is unavailable, implement input validation on the pdf_file_path parameter to reject or escape external URLs, allowing only file‑system paths or a whitelist of trusted domains.
  • Configure network controls such as firewall rules or a proxy to restrict outbound connections from the pdf‑tools‑mcp service to only necessary destinations, mitigating the impact of any remaining SSRF paths.

Generated by OpenCVE AI on September 20, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the component pdf-tools-mcp. Performing a manipulation of the argument pdf_file_path results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title 0717376 cowork_bench pdf-tools-mcp server.py ControlFlowNode server-side request forgery
First Time appeared 0717376
0717376 cowork Bench
Weaknesses CWE-918
CPEs cpe:2.3:a:0717376:cowork_bench:*:*:*:*:*:*:*:*
Vendors & Products 0717376
0717376 cowork Bench
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

0717376 Cowork Bench
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T16:24:06.480Z

Reserved: 2026-09-19T21:54:42.237Z

Link: CVE-2026-94051

cve-icon Vulnrichment

Updated: 2026-09-21T16:23:50.196Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T21:16:55.597

Modified: 2026-09-21T17:19:19.273

Link: CVE-2026-94051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)