OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 15:17
Updated : 2026-09-04 18:18
NVD link : CVE-2026-85675
Mitre link : CVE-2026-85675
CVE.ORG link : CVE-2026-85675
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
