CVE-2025-50736

MEDIUM

Byaidu PDFMathTranslate <1.9.9 - Open Redirect

Title source: llm
STIX 2.1

Description

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for phishing attacks or to bypass security filters.

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
pypi/pdf2zh PyPI
Published Oct 30, 2025
Tracked Since Feb 18, 2026