rootpwn

medium · CVSS v3 6.3 · CVSS v4 5.3

CVE-2026-94051

CVE-2026-94051 exposes a server‑side request forgery flaw in pdf-tools-mcp’s ControlFlowNode function. The vulnerability allows remote attac

Overview

CVE-2026-94051 exposes a server‑side request forgery flaw in pdf-tools-mcp’s ControlFlowNode function. The vulnerability allows remote attackers to manipulate the pdf_file_path argument and force the server to make arbitrary HTTP requests. It is publicly known and could be abused in a rolling‑release environment without a fixed version.

Description

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of the component pdf-tools-mcp. Performing a manipulation of the argument pdf_file_path results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Impact

The flaw compromises confidentiality, integrity, and availability of the server by enabling attackers to exfiltrate data, alter server state, or trigger denial‑of‑service conditions. Defenders managing instances of pdf-tools-mcp are at risk of unauthorized data access and potential service disruption.

Remediation

Apply the vendor’s patch once released or upgrade to a version that removes the vulnerable ControlFlowNode implementation. In the interim, restrict network access to the pdf-tools-mcp service, validate and sanitize pdf_file_path inputs, and enforce strict outbound request whitelisting.

Risk context

Medium severity (CVSS 6.3) with no EPSS data; the public nature of the exploit and lack of vendor response elevate the urgency for immediate mitigation.

Affected products

  • 0717376 cowork_bench pdf-tools-mcp
  • pdf-tools-mcp

Scores

Severity
medium
CVSS v2
6.5
CVSS v3
6.3
CVSS v4
5.3
EPSS

srf pdf-tools-mcp server-side request forgery remote exploitation defense

← All CVEs