Server-Side Request Forgery Vulnerability in cowork_bench PDF Tools from 0717376
CVE-2026-94051

5.3MEDIUM

Key Information:

Vendor

0717376

Vendor
CVE Published:
20 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-94051?

A vulnerability exists in the pdf-tools-mcp component of cowork_bench, specifically within the ControlFlowNode function of the server.py file. An attacker could manipulate the pdf_file_path argument to perform server-side request forgery, enabling remote execution of malicious commands. This vulnerability has been made public and poses a serious risk, as it can allow unauthorized access to internal systems. The continuous delivery model of the product complicates version tracking, leaving all instances of the affected product vulnerable until addressed. Despite being notified early, the vendor has not yet provided any updates or fixes.

Affected Version(s)

cowork_bench d943e75bc0fc8e3b27141979300cd8cbcd1e890d

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xh1Xxhg (VulDB User)
VulDB CNA Team
.