CVE-2026-108554
PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.
| CWE | CWE-918 |
| Vendor | pdfmathtranslate |
| Product | pdfmathtranslate |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for pdfmathtranslate pdfmathtranslate
Be the first to know when new medium vulnerabilities affecting pdfmathtranslate pdfmathtranslate are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
PDFMathTranslate / PDFMathTranslate
0 โค 1.9.11
References
github.com: https://github.com/PDFMathTranslate/PDFMathTranslate/issues/1188 github.com: https://github.com/PDFMathTranslate/PDFMathTranslate github.com: https://github.com/PDFMathTranslate/PDFMathTranslate/blob/0f0618d3303d064d97e7adb77557b21236c6cee0/pdf2zh/gui.py#L149-L179 github.com: https://github.com/PDFMathTranslate/PDFMathTranslate/blob/0f0618d3303d064d97e7adb77557b21236c6cee0/pdf2zh/gui.py#L257-L269 vulncheck.com: https://www.vulncheck.com/advisories/pdfmathtranslate-through-1.9.11-ssrf-via-gradio-web-gui-link-input
Credits
George Chen