Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108554— PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input

Quick assessment

Affected
PDFMathTranslate PDFMathTranslate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PDFMathTranslate(pdf2zh)1.9.11 及之前版本存在一个服务器端请求伪造(SSRF)漏洞,允许未认证的攻击者通过 Link 输入字段使服务器获取任意 URL。translate_file 处理程序将用户提供的 URL 传递给 download_with_limit,且未对 URL 的协议(scheme)和地址进行验证,从而使攻击者能够访问内部服务和云元数据端点,并获取返回的 PDF 文件。

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
PDFMathTranslate PDFMathTranslate ≤ 1.9.11 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108554

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input
Source: CVE Program / CVE List V5
Vulnerability Description
PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PDFMathTranslate PDFMathTranslate 0 ~ 1.9.11 -

II. Public POCs for CVE-2026-108554

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108554

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-108554 (1)

Proof of Concept for CVE-2026-108554 (1)

Other References for CVE-2026-108554 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-108554

No comments yet


Leave a comment