A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mc…
Medium CVSS 6.3
Summary
A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the component pdf-tools-mcp. Performing a manipulation of the argument pdf_file_path results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to pro…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/0717376/cowork_bench/
- https://github.com/0717376/cowork_bench/issues/1
- https://github.com/Xh1Xxhg/public_exp/issues/7
- https://vuldb.com/cve/CVE-2026-94051
- https://vuldb.com/submit/949604
- https://vuldb.com/vuln/407980
- https://vuldb.com/vuln/407980/cti
Timeline
- nvd_ingest NVD