DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-X8GV-G2G3-65FJ: CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

Vulnerability ID: GHSA-X8GV-G2G3-65FJ
CVSS Score: 8.2
Published: 2026-10-02

An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.

TL;DR

A DNS-rebinding SSRF vulnerability in the SiYuan Kernel AI Agent tools allows remote attackers to bypass private IP validation and access internal networks or cloud metadata by exploiting a Time-of-Check to Time-of-Use (TOCTOU) window in DNS resolution.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-918
  • Attack Vector: Network
  • CVSS v3.1 Score: 8.2 (High)
  • EPSS Score: 0.00362 (Percentile: 27.74%)
  • Impact: Confidentiality: High, Scope: Changed
  • Exploit Status: Proof of Concept (PoC) verified
  • CISA KEV Status: Not Listed

Affected Systems

  • SiYuan (思源笔记) Kernel
  • SiYuan: <= 3.8.0 (Fixed in: 3.8.1)

Code Analysis

Commit: dd2778b

Fix: Implement connection-time IP validation dialer (ssrfSafeDialContext) for AI HTTP client requests to prevent DNS Rebinding.

Mitigation Strategies

  • Upgrade SiYuan Kernel to version 3.8.1 or above to enforce connection-level IP validation.
  • Configure local firewall rules to block outbound TCP traffic to loopback interfaces and link-local cloud metadata endpoints.
  • Deploy internal DNS resolution filtering (e.g., DNSMASQ or firewall-level DNS inspection) to discard responses returning private IP spaces for external domains.

Remediation Steps:

  1. Navigate to the SiYuan installation or deployment manager and initiate a check for updates.
  2. Install version 3.8.1 of the SiYuan application, ensuring the service is restarted.
  3. Verify that the AI tools http_request and web_fetch are functioning properly on public sites while blocking local network queries.

References


Read the full report for GHSA-X8GV-G2G3-65FJ on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)