Impact
The vulnerability resides in the ControlFlowNode function of the pdf-tools-mcp component inside cowork_bench. By manipulating the pdf_file_path argument, an attacker can cause the server to request arbitrary URLs, leading to server‑side request forgery (SSRF). This flaw does not require authentication and can be triggered remotely. An exploit has already been published, and the product uses a rolling release model, so no specific fixed revision has been made public yet.
Affected Systems
The affected product is 0717376 cowork_bench. No specific version information is available because the project provides continuous delivery via rolling releases. The vulnerability is present in the code base up to commit d943e75bc0fc8e3b27141979300cd8cbcd1e890d.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate. The EPSS score is not available, but the public nature of the exploit and the lack of a patch suggest a realistic threat. The flaw is listed as a server‑side request forgery (CWE‑918).
OpenCVE Enrichment