Unknown · Cowork Bench · CVE-2026-94051
**Name of the Vulnerable Software and Affected Versions**
0717376 cowork bench versions up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d
**Description**
In the pdf-tools-mcp component, the `ControlFlowNode()` function within the file local servers/pdf-tools-mcp/pdf tools mcp/server.py is susceptible to server-side request forgery (SSRF). This occurs when the `pdf file path` argument is manipulated, allowing a remote attacker to initiate unauthorized requests from the server.
**Recommendations**
As a temporary workaround, restrict the use of the `pdf file path` argument in the `ControlFlowNode()` function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.