HIGH 8.7 NVD
CVE-2026-85675
OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with
OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context.
References
- https://github.com/camel-ai/owl
- https://github.com/camel-ai/owl/blob/fba1dd5b3a9e8cc15f16221bb002cca7e3de2d9d/owl/utils/do
- https://github.com/camel-ai/owl/issues/615
- https://www.vulncheck.com/advisories/owl-documentprocessingtoolkit-server-side-request-for
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.