PatchSiren cyber security CVE debrief
CVE-2026-94051 0717376 CVE debrief
A vulnerability was found in cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. The function ControlFlowNode in local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py is affected by a server-side request forgery vulnerability. The exploit has been made public and could be used. This product uses a rolling release for continuous delivery, so no version details for affected or updated releases are available.
- Vendor
- 0717376
- Product
- cowork_bench
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-20
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-20
- Advisory updated
- 2026-09-20
Who should care
Defenders responsible for cowork_bench deployments should assess exposure and prioritize verification of inventory and potential compensating controls. This includes reviewing system logs for signs of exploitation and ensuring that security teams are aware of the vulnerability's public exploitability.
Why it matters
CVE-2026-94051 is a server-side request forgery vulnerability in cowork_bench that has been publicly exploited. Defenders should prioritize verifying inventory, assessing exposure, and monitoring for potential exploitation attempts.
- Verify inventory for cowork_bench deployments
- Assess exposure to server-side request forgery
- Monitor for potential exploitation attempts
- Consider compensating controls until an official fix is available
Technical summary
The ControlFlowNode function in local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of cowork_bench is vulnerable to server-side request forgery. The vulnerability is triggered by manipulating the pdf_file_path argument. The exploit has been made public, and the product uses a rolling release model, making it difficult to determine affected or updated versions. This vulnerability allows remote attackers to potentially access internal resources, and defenders should prioritize verifying inventory and assessing exposure.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, given the public availability of the exploit.
Recommended defensive actions
- Verify the presence of cowork_bench in your inventory
- Assess exposure to the server-side request forgery vulnerability
- Monitor for potential exploitation attempts
- Consider compensating controls until an official fix is available
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source metadata indicate a server-side request forgery vulnerability in cowork_bench. The exploit has been made public, but no version details for affected or updated releases are available due to the rolling release model.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94051 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94051
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94051 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94051
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/0717376/cowork_bench/
-
Source reference
Unverified legacy reference
URL: https://github.com/0717376/cowork_bench/issues/1
-
Source reference
Unverified legacy reference
URL: https://github.com/Xh1Xxhg/public_exp/issues/7
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-94051
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/949604
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/407980
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/407980/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.