---
id: CVE-2025-50736
aliases:
  - GHSA-pfrv-63w8-q7rq
  - PYSEC-2026-1760
title: Byaidu PDFMathTranslate vulnerable to open redirect
summary: Byaidu PDFMathTranslate vulnerable to open redirect
severity: low
vendor: pdf2zh
product: pdf2zh
ecosystem: pip
affected:
  - pdf2zh
published: '2025-10-30'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pfrv-63w8-q7rq'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-50736'
  - url: 'https://github.com/Byaidu/PDFMathTranslate'
  - url: 'https://github.com/fai1424/Vulnerability-Research/tree/main/CVE-2025-50736'
  - url: 'https://hackmd.io/@fai1424/SJz7ttVWxe'
  - url: 'https://pdf2zh.com'
tags:
  - osv
  - pip
epss: 0.00211
epssPercentile: 0.10125
ingestedAt: '2026-07-08T18:25:51.754Z'
---

## Overview

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for phishing attacks or to bypass security filters.

## Affected packages

- `pdf2zh`

## Remediation

Refer to the advisory for the patched release.
