CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel
Vulnerability ID: GHSA-X8GV-G2G3-65FJ
CVSS Score: 8.2
Published: 2026-10-02
An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.
TL;DR
A DNS-rebinding SSRF vulnerability in the SiYuan Kernel AI Agent tools allows remote attackers to bypass private IP validation and access internal networks or cloud metadata by exploiting a Time-of-Check to Time-of-Use (TOCTOU) window in DNS resolution.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-918
- Attack Vector: Network
- CVSS v3.1 Score: 8.2 (High)
- EPSS Score: 0.00362 (Percentile: 27.74%)
- Impact: Confidentiality: High, Scope: Changed
- Exploit Status: Proof of Concept (PoC) verified
- CISA KEV Status: Not Listed
Affected Systems
- SiYuan (思源笔记) Kernel
-
SiYuan: <= 3.8.0 (Fixed in:
3.8.1)
Code Analysis
Commit: dd2778b
Fix: Implement connection-time IP validation dialer (ssrfSafeDialContext) for AI HTTP client requests to prevent DNS Rebinding.
Mitigation Strategies
- Upgrade SiYuan Kernel to version 3.8.1 or above to enforce connection-level IP validation.
- Configure local firewall rules to block outbound TCP traffic to loopback interfaces and link-local cloud metadata endpoints.
- Deploy internal DNS resolution filtering (e.g., DNSMASQ or firewall-level DNS inspection) to discard responses returning private IP spaces for external domains.
Remediation Steps:
- Navigate to the SiYuan installation or deployment manager and initiate a check for updates.
- Install version 3.8.1 of the SiYuan application, ensuring the service is restarted.
- Verify that the AI tools http_request and web_fetch are functioning properly on public sites while blocking local network queries.
References
- GHSA Advisory Database Entry
- SiYuan Security Advisory
- VulnCheck Technical Advisory
- OSV Entry for GHSA-x8gv-g2g3-65fj
- CVE.org Official Record
Read the full report for GHSA-X8GV-G2G3-65FJ on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)