HighVulnerability
GHSA-x8gv-g2g3-65fj: SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
- Identifier
- GHSA-x8gv-g2g3-65fj
- Published
- Record updated
Summary
SiYuan's AI Agent tools `http_request` (`util.HTTPRequest`) and `web_fetch` (`util.WebFetch`) check outbound hosts with `CheckHostSSRF`, which resolves DNS once at guard time, while the actual connection resolves DNS again through the default `net.Dialer` with no connect-time private-IP check. An attacker-controlled domain can return a public IP to the guard and a private or metadata address such as `169.254.169.254` to the connection, bypassing the SSRF defense. Affected versions are `<= 3.8.0`, verified on v3.8.0, and the flaw is an incomplete-fix variant of GHSA-rg26-cg95-gq6p.
Mitigation
Fixed in 3.8.1
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database