PatchSiren

PDFMathTranslate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM PDFMathTranslate CVE published 2026-10-10

CVE-2026-108554

CVE-2026-108554 is a server-side request forgery vulnerability in PDFMathTranslate (pdf2zh) through 1.9.11. The vulnerability allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve [truncated]