Skip to main content

Kernel: SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)

0
High
Published: 10/02/2026 (10/02/2026, 23:17:16 UTC)
Source: GCVE Database
Product: github.com/siyuan-note/siyuan/kernel

Description

SiYuan Agent Tools versions up to 3.8.0 contain a Server-Side Request Forgery (SSRF) vulnerability due to a DNS rebinding time-of-check to time-of-use (TOCTOU) flaw. The vulnerability arises because the SSRF protection performs a single DNS resolution at guard time but does not verify the IP address at connection time, allowing an attacker-controlled domain to bypass the check by returning a public IP initially and a private or loopback IP on connection. This enables access to internal services such as cloud instance metadata. The issue affects the AI Agent tools' http_request and web_fetch components and was patched in version 3.8.1.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Affected software

Goghsa
github.com/siyuan-note/siyuan/kernel
Affected versions
<0.0.0-20260813142806-dd2778b70d02

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:38:21 UTC

Technical Analysis

The SiYuan kernel's AI Agent tools (http_request and web_fetch) implement SSRF protection via the CheckHostSSRF function, which performs a single DNS resolution to block private, loopback, and link-local IPs at guard time. However, the actual network connection performs a second DNS resolution without enforcing the same IP restrictions, allowing a DNS rebinding TOCTOU attack. An attacker-controlled domain can respond with a public IP during the guard check and a private or loopback IP during connection, bypassing SSRF defenses and accessing internal resources. This incomplete fix variant relates to a prior advisory (GHSA-rg26-cg95-gq6p) where connect-time checks were not applied to the agent tool paths. The vulnerability was confirmed on version 3.8.0 and fixed in 3.8.1.

Potential Impact

An attacker who can control the domain name requested by the AI Agent tools can exploit this vulnerability to bypass SSRF protections and access internal or cloud metadata services that should be blocked. This could lead to unauthorized disclosure of sensitive internal information. The exploitation probability is considered low to moderate, requiring attacker influence over the AI Agent's URL input (e.g., via prompt injection). The vulnerability is exploitable in default configurations with SafeMode both enabled and disabled.

Mitigation Recommendations

A patch is available in SiYuan version 3.8.1 that fixes this vulnerability by properly enforcing connect-time IP checks. Users should upgrade to version 3.8.1 or later. No additional mitigations are required if the patch is applied. Until patched, restricting access to the AI Agent tools or limiting attacker control over URLs may reduce risk but is not a complete mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-x8gv-g2g3-65fj
Osv Schema Version
1.4.0
Ecosystems
["Go"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6ac139a8a43b0b3b89d69ac2

Added to database: 10/03/2026, 17:21:44 UTC

Last enriched: 10/03/2026, 17:38:21 UTC

Last updated: 10/03/2026, 22:37:38 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses