Server-Side Request Forgery Vulnerability in cowork_bench PDF Tools from 0717376
CVE-2026-94051
Key Information:
- Vendor
0717376
- Status
- Vendor
- CVE Published:
- 20 September 2026
Badges
What is CVE-2026-94051?
A vulnerability exists in the pdf-tools-mcp component of cowork_bench, specifically within the ControlFlowNode function of the server.py file. An attacker could manipulate the pdf_file_path argument to perform server-side request forgery, enabling remote execution of malicious commands. This vulnerability has been made public and poses a serious risk, as it can allow unauthorized access to internal systems. The continuous delivery model of the product complicates version tracking, leaving all instances of the affected product vulnerable until addressed. Despite being notified early, the vendor has not yet provided any updates or fixes.
Affected Version(s)
cowork_bench d943e75bc0fc8e3b27141979300cd8cbcd1e890d
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
