CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-X8GV-G2G3-65FJ

CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 3, 2026·7 min read·4 visits

Executive Summary (TL;DR)

A DNS-rebinding SSRF vulnerability in the SiYuan Kernel AI Agent tools allows remote attackers to bypass private IP validation and access internal networks or cloud metadata by exploiting a Time-of-Check to Time-of-Use (TOCTOU) window in DNS resolution.

An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.

Vulnerability Overview

The vulnerability identified as CVE-2026-82234 is a Server-Side Request Forgery (SSRF) flaw in SiYuan, an open-source personal knowledge management system. The vulnerability specifically affects the AI Agent integration within the SiYuan Kernel, which exposes tools designed to retrieve external web pages and interface with third-party web services. These capabilities are exposed through functions such as util.HTTPRequest and util.WebFetch which run inside the core application environment.

To prevent abuse, the developers introduced SSRF validation logic called CheckHostSSRF to screen requested hosts before connection attempts. However, because this validation occurs during the URL parsing phase independently of the socket-creation phase, a Time-of-Check to Time-of-Use (TOCTOU) gap is introduced. Attackers can leverage this window of vulnerability using DNS-rebinding techniques, allowing arbitrary network requests to bypass the application's verification gates and access local resources.

Root Cause Analysis

The root cause of this vulnerability lies in a critical architectural mismatch between validation logic and connection-level network execution. The validation function CheckHostSSRF resolves the provided domain name using standard DNS query mechanisms. If the resolved IP address belongs to public network spaces, the address passes validation, and the application proceeds to execute the request using the default HTTP client client instance.

However, Go's default http.Client transport does not reuse the IP address resolved during the parsing validation step. Instead, when initiating the connection, the client's underlying network dialer performs an entirely separate DNS query to resolve the domain to an IP address for the socket connection. An attacker controlling the DNS server can exploit this by returning a public IP during the first resolution and an internal IP during the second resolution.

This behavior is documented as a Classic DNS-Rebinding attack pattern. Because the internal validation mechanism lacks IP pinning, it fails to bind the resolved socket connection to the validated destination. The connection-level socket is thus opened directly to internal loopback interfaces or cloud metadata servers without passing subsequent checks.

Code Analysis

In the vulnerable implementation found in version 3.8.0, the AI agent's HTTP request utility relies on a default browser request instance via httpclient.NewBrowserRequest(). This client uses standard Go transport layers that lack custom DNS validation or socket connection interceptors. The code first performs the host validation using CheckHostSSRF but fails to pass any state or IP pinning parameters to the browser request that executes immediately afterward.

// Vulnerable execution path in v3.8.0
func HTTPRequest(method, rawURL string, headers map[string]string, body string) ... {
    // ...
    // Parse-time check only: validation occurs here
    if err := CheckHostSSRF(host); err != nil {
        return 0, "", "", err
    }
    
    // Connection-time resolution occurs here without IP validation
    request := httpclient.NewBrowserRequest()
    resp, err := sendByMethod(request, method, rawURL)
}

The patch committed in dd2778b70d020b15491ef7418f5f63214583cd63 mitigates this vulnerability by replacing the default HTTP client with a hardcoded ssrfSafeClient. This specialized client overrides the transport's dial context with a custom dialer function called ssrfSafeDialContext. Instead of letting the default dialer resolve the hostname and dial the socket, the custom function handles name resolution directly and filters out private IP addresses before the socket connection is initiated.

// Patched execution path in v3.8.1 implementing ssrfSafeDialContext
func ssrfSafeDialContext(timeout time.Duration) func(ctx context.Context, network, addr string) (net.Conn, error) {
    dialer := &net.Dialer{Timeout: timeout}
    return func(ctx context.Context, network, addr string) (net.Conn, error) {
        // ...
        // DNS resolution is performed directly in the dialer
        ips, err := net.DefaultResolver.LookupIPAddr(ctx, host)
        for _, ipAddr := range ips {
            if isPrivateIP(ipAddr.IP) {
                continue // Private IPs are explicitly rejected during the connection dial phase
            }
            // Directly dialing the resolved, validated IP address pins the connection and prevents rebinding
            return dialer.DialContext(ctx, network, net.JoinHostPort(ipAddr.IP.String(), port))
        }
    }
}

Exploitation Methodology

To execute this exploit, an attacker must configure an authoritative DNS server to handle queries for a target domain under their control. The DNS server is programmed to alternate its responses or use an extremely low Time-To-Live (TTL) of zero seconds. The sequence of DNS resolutions must return a public IP for the first query and a local IP address for the subsequent connection query.

When the victim's AI agent processes an instruction containing a reference to the attacker-controlled domain, the application makes its first query. The DNS server returns a benign public IP address such as 203.0.113.1, which passes the CheckHostSSRF check. Immediately after validation, the HTTP client initiates the connection and issues a second DNS query because the TTL of the first response was set to zero.

The authoritative DNS server responds to this second query with a target internal IP address such as 127.0.0.1 or the link-local metadata IP 169.254.169.254. The Go HTTP client establishes the TCP connection directly to this private IP. This allows the attacker to execute arbitrary HTTP methods against internal API endpoints, loopback web servers, or cloud instance metadata services, completely bypassing firewalls and external boundary protections.

Impact Assessment

The security impact of this vulnerability is significant, as it transforms a simple personal knowledge application into an initial access vector for local networks. If the SiYuan application is hosted within a cloud computing environment (such as AWS, GCP, or Azure), an attacker can access the Instance Metadata Service (IMDS). Through IMDS access, the attacker can extract sensitive system credentials, service role privileges, and internal configuration details.

On localized deployments, the vulnerability allows the attacker to interact with other containerized services sharing the loopback interface or the internal Docker network. Attackers can issue HTTP requests to internal databases, memory caches, and management dashboards that do not require authentication for local connections. This can lead to database corruption, execution of administrative commands, or exfiltration of sensitive localized data assets.

The vulnerability is assigned a CVSS score of 8.2, reflecting its remote exploitability, low complexity, and high confidentiality impact. Because the vulnerability changes the security scope from the application context to the underlying network environment, it receives a Scope: Changed metric, highlighting its potential to expose adjacent internal network segments.

Remediation and Prevention

Remediation of CVE-2026-82234 requires updating the SiYuan Kernel to version 3.8.1 or later. This version replaces the insecure browser HTTP requests with the pinned client architecture that enforces IP validation during the dial context phase. Organizations hosting older versions of SiYuan must isolate the application using strict network segmentation to limit the blast radius of any outbound traffic.

Temporary workarounds include configuring local firewall rules (such as iptables or AWS Security Groups) to block all outbound traffic from the SiYuan server to private subnets or the metadata endpoint (169.254.169.254). Implementing DNS filtering solutions that detect and drop responses containing RFC1918 or loopback addresses (DNS Rebinding protection) can also block this attack vector at the network edge.

Developers should learn from this vulnerability by ensuring that validation and connection phases are structurally linked. Name resolution should occur once, and the validated IP address must be utilized directly to establish the network socket, avoiding any subsequent lookup calls. Implementing a custom dialer context that enforces strict IP range checking during socket creation is the recommended best practice for all Go-based applications handling user-supplied URLs.

Official Patches

siyuan-noteCommit implementing connection-level IP-pinning context dialer
siyuan-noteOfficial GitHub Release notes for version 3.8.1 containing the patch

Fix Analysis (1)

Technical Appendix

CVSS Score
8.2/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
EPSS Probability
0.36%
Top 72% most exploited

Affected Systems

SiYuan (思源笔记) Kernel

Affected Versions Detail

Product
Affected Versions
Fixed Version
SiYuan
siyuan-note
<= 3.8.03.8.1
AttributeDetail
CWE IDCWE-918
Attack VectorNetwork
CVSS v3.1 Score8.2 (High)
EPSS Score0.00362 (Percentile: 27.74%)
ImpactConfidentiality: High, Scope: Changed
Exploit StatusProof of Concept (PoC) verified
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-918
Server-Side Request Forgery (SSRF)

The web application receives a URL from an upstream component or user input, and requests the URL without properly validating that the host resolves to a non-private IP address at connection-time, leaving it vulnerable to DNS rebinding.

References & Sources

  • [1]GHSA Advisory Database Entry
  • [2]SiYuan Security Advisory
  • [3]VulnCheck Technical Advisory
  • [4]OSV Entry for GHSA-x8gv-g2g3-65fj
  • [5]CVE.org Official Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•19 minutes ago•CVE-2026-19481
7.5

CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

A critical remote, unauthenticated Denial of Service (DoS) vulnerability in @fastify/busboy (<= 3.2.0) allows attackers to crash the Node.js process. By submitting a crafted multipart/form-data request with a header key matching an inherited property of Object.prototype (like __proto__ or constructor), the internal HeaderParser triggers a synchronous TypeError.

Amit Schendel
Amit Schendel
1 views•7 min read
•about 1 hour ago•GHSA-P23F-CM6Q-2QP8
8.6

GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP

SiYuan is an open-source personal knowledge management system. Its Model Context Protocol (MCP) implementation within the asset.upload tool contains a path-traversal and workspace boundary bypass flaw. This allows remote AI models—acting on behalf of attackers via malicious prompts or documents—to import and read sensitive host-system files, such as private keys and system configurations, through absolute path inputs.

Alon Barad
Alon Barad
3 views•6 min read
•about 3 hours ago•CVE-2026-104861
7.5

CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.

Amit Schendel
Amit Schendel
5 views•9 min read
•about 4 hours ago•CVE-2026-10032
6.1

CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core

CVE-2026-10032 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Google's @a2ui/web_core Node.js library. The vulnerability is located within the openUrl utility function, which processes and opens dynamic URLs defined in layout configurations. Because the function fails to sanitize or validate the target URL scheme before passing it to the window.open browser sink, an attacker can specify a javascript: pseudo-protocol to execute arbitrary client-side script in the context of the host origin.

Amit Schendel
Amit Schendel
7 views•7 min read
•about 5 hours ago•CVE-2026-59944
6.1

CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 6 hours ago•GHSA-QXPP-QJG8-X4JV
9.9

GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

A critical Broken Object Level Authorization (BOLA) vulnerability was identified in Trigger.dev before version v4.5.2. An authenticated attacker could trigger a run replay and supply an arbitrary target environmentId belonging to a completely different tenant. Because the server failed to validate whether the target environment belonged to the same project or organization as the source run, it would execute the task within the victim's environment, resulting in unauthorized cross-tenant write operations and remote task execution.

Alon Barad
Alon Barad
10 views•5 min read