Executive brief
Surya is an OCR and document intelligence tool that includes a web-based screenshot server. An unauthenticated attacker can read any image or PDF file on the host system by manipulating file path parameters in the /info, /page, and /process API routes, bypassing file access controls and potentially exposing sensitive documents and data.
Technical details
The vulnerability is an unauthenticated arbitrary file read flaw in the screenshot server's /info, /page, and /process routes. The routes accept raw file_path parameters that are passed directly to Image.open() and pypdfium2.PdfDocument() without proper path validation or sanitization, enabling directory traversal attacks. An attacker with network access to the screenshot server can supply arbitrary absolute or relative file paths to read any image or PDF file accessible to the application process. The /info endpoint can also be abused as an existence oracle to enumerate files on the filesystem. No authentication or special preconditions are required beyond network connectivity to the server.
Affected products
- Datalab surya 0.22.1
Timeline
- 2026-09-04: disclosed