Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SSRF vulnerability in OWL DocumentProcessingToolkit

OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that allows attackers to inject malicious URLs through prompt injection to fetch internal resources.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-9c7r-jxm8-hgg2