CVE-2026-108554: Pdfmathtranslate
Medium severity, CVSS 5.3.
PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs.
Affected products
- Pdfmathtranslate Pdfmathtranslate: up to and including 1.9.11
Published 2026-10-10. Last modified 2026-10-10.