- CVSS
- HIGH · 7.5v3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Published
- 2026-09-04
- Weakness
- CWE-918
- Source
- nvd.nist.gov/vuln/detail/CVE-2026-85675
Description
OWL’s DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context.
References
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2026-85675 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.