CVE-2026-85675

OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 15:17

Updated : 2026-09-04 18:18


NVD link : CVE-2026-85675

Mitre link : CVE-2026-85675

CVE.ORG link : CVE-2026-85675


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)