Kernel: SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
SiYuan Agent Tools versions up to 3.8.0 contain a Server-Side Request Forgery (SSRF) vulnerability due to a DNS rebinding time-of-check to time-of-use (TOCTOU) flaw. The vulnerability arises because the SSRF protection performs a single DNS resolution at guard time but does not verify the IP address at connection time, allowing an attacker-controlled domain to bypass the check by returning a public IP initially and a private or loopback IP on connection. This enables access to internal services such as cloud instance metadata. The issue affects the AI Agent tools' http_request and web_fetch components and was patched in version 3.8.1.
AI Analysis
Technical Summary
The SiYuan kernel's AI Agent tools (http_request and web_fetch) implement SSRF protection via the CheckHostSSRF function, which performs a single DNS resolution to block private, loopback, and link-local IPs at guard time. However, the actual network connection performs a second DNS resolution without enforcing the same IP restrictions, allowing a DNS rebinding TOCTOU attack. An attacker-controlled domain can respond with a public IP during the guard check and a private or loopback IP during connection, bypassing SSRF defenses and accessing internal resources. This incomplete fix variant relates to a prior advisory (GHSA-rg26-cg95-gq6p) where connect-time checks were not applied to the agent tool paths. The vulnerability was confirmed on version 3.8.0 and fixed in 3.8.1.
Potential Impact
An attacker who can control the domain name requested by the AI Agent tools can exploit this vulnerability to bypass SSRF protections and access internal or cloud metadata services that should be blocked. This could lead to unauthorized disclosure of sensitive internal information. The exploitation probability is considered low to moderate, requiring attacker influence over the AI Agent's URL input (e.g., via prompt injection). The vulnerability is exploitable in default configurations with SafeMode both enabled and disabled.
Mitigation Recommendations
A patch is available in SiYuan version 3.8.1 that fixes this vulnerability by properly enforcing connect-time IP checks. Users should upgrade to version 3.8.1 or later. No additional mitigations are required if the patch is applied. Until patched, restricting access to the AI Agent tools or limiting attacker control over URLs may reduce risk but is not a complete mitigation.
Kernel: SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
Description
SiYuan Agent Tools versions up to 3.8.0 contain a Server-Side Request Forgery (SSRF) vulnerability due to a DNS rebinding time-of-check to time-of-use (TOCTOU) flaw. The vulnerability arises because the SSRF protection performs a single DNS resolution at guard time but does not verify the IP address at connection time, allowing an attacker-controlled domain to bypass the check by returning a public IP initially and a private or loopback IP on connection. This enables access to internal services such as cloud instance metadata. The issue affects the AI Agent tools' http_request and web_fetch components and was patched in version 3.8.1.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The SiYuan kernel's AI Agent tools (http_request and web_fetch) implement SSRF protection via the CheckHostSSRF function, which performs a single DNS resolution to block private, loopback, and link-local IPs at guard time. However, the actual network connection performs a second DNS resolution without enforcing the same IP restrictions, allowing a DNS rebinding TOCTOU attack. An attacker-controlled domain can respond with a public IP during the guard check and a private or loopback IP during connection, bypassing SSRF defenses and accessing internal resources. This incomplete fix variant relates to a prior advisory (GHSA-rg26-cg95-gq6p) where connect-time checks were not applied to the agent tool paths. The vulnerability was confirmed on version 3.8.0 and fixed in 3.8.1.
Potential Impact
An attacker who can control the domain name requested by the AI Agent tools can exploit this vulnerability to bypass SSRF protections and access internal or cloud metadata services that should be blocked. This could lead to unauthorized disclosure of sensitive internal information. The exploitation probability is considered low to moderate, requiring attacker influence over the AI Agent's URL input (e.g., via prompt injection). The vulnerability is exploitable in default configurations with SafeMode both enabled and disabled.
Mitigation Recommendations
A patch is available in SiYuan version 3.8.1 that fixes this vulnerability by properly enforcing connect-time IP checks. Users should upgrade to version 3.8.1 or later. No additional mitigations are required if the patch is applied. Until patched, restricting access to the AI Agent tools or limiting attacker control over URLs may reduce risk but is not a complete mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x8gv-g2g3-65fj
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ac139a8a43b0b3b89d69ac2
Added to database: 10/03/2026, 17:21:44 UTC
Last enriched: 10/03/2026, 17:38:21 UTC
Last updated: 10/03/2026, 22:37:38 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.