CVE-2026-85675

Source
https://cve.org/CVERecord?id=CVE-2026-85675
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85675.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85675
Published
2026-09-04T14:32:28Z
Modified
2026-10-08T02:52:16Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OWL DocumentProcessingToolkit Server-Side Request Forgery via URL Fetching
Details

OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85675.json"
}
References

Affected packages

Git / github.com/camel-ai/owl

Affected ranges

Type
GIT
Repo
https://github.com/camel-ai/owl
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85675.json"