PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94051 0717376 CVE debrief

A vulnerability was found in cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. The function ControlFlowNode in local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py is affected by a server-side request forgery vulnerability. The exploit has been made public and could be used. This product uses a rolling release for continuous delivery, so no version details for affected or updated releases are available.

Vendor
0717376
Product
cowork_bench
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-20
Original CVE updated
2026-09-20
Advisory published
2026-09-20
Advisory updated
2026-09-20

Who should care

Defenders responsible for cowork_bench deployments should assess exposure and prioritize verification of inventory and potential compensating controls. This includes reviewing system logs for signs of exploitation and ensuring that security teams are aware of the vulnerability's public exploitability.

Why it matters

CVE-2026-94051 is a server-side request forgery vulnerability in cowork_bench that has been publicly exploited. Defenders should prioritize verifying inventory, assessing exposure, and monitoring for potential exploitation attempts.

  • Verify inventory for cowork_bench deployments
  • Assess exposure to server-side request forgery
  • Monitor for potential exploitation attempts
  • Consider compensating controls until an official fix is available

Technical summary

The ControlFlowNode function in local_servers/pdf-tools-mcp/pdf_tools_mcp/server.py of cowork_bench is vulnerable to server-side request forgery. The vulnerability is triggered by manipulating the pdf_file_path argument. The exploit has been made public, and the product uses a rolling release model, making it difficult to determine affected or updated versions. This vulnerability allows remote attackers to potentially access internal resources, and defenders should prioritize verifying inventory and assessing exposure.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, given the public availability of the exploit.

Recommended defensive actions

  • Verify the presence of cowork_bench in your inventory
  • Assess exposure to the server-side request forgery vulnerability
  • Monitor for potential exploitation attempts
  • Consider compensating controls until an official fix is available
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source metadata indicate a server-side request forgery vulnerability in cowork_bench. The exploit has been made public, but no version details for affected or updated releases are available due to the rolling release model.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94051 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94051

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94051 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94051

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.