Vulnerability GHSA-x8gv-g2g3-65fj

High Risk
HIGH RISK
CVSS Score: 8.2
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
10 hours ago
October 02, 2026 at 11:17 PM UTC
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
<0.0.0-20260813142806-dd2778b70d02
<0.0.0-20260813142806-dd2778b70d02

Summary

SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)

Details

Security Advisory — SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)

Field Value
Disclosed by joysinleung ([email protected])
Report date 2026-08-13
Product SiYuan (思源笔记) — siyuan-note/siyuan
Go module github.com/siyuan-note/siyuan/kernel
Affected versions <= 3.8.0 (latest release at report time; dynamically verified on v3.8.0)
Patched versions 3.8.1
Component kernel/util/httprequest.go (CheckHostSSRF), kernel/mcp/tools/http_request.go, kernel/util/webfetch.go, kernel/util/net.go (SSRFSafeDialer)
Relationship to prior advisory Incomplete-fix variant of GHSA-rg26-cg95-gq6p (SSRF main-vector remediation). See §Relationship.
EPSS (exploitation probability) Low–Moderate. Requires the attacker to influence an AI Agent / MCP client into fetching an attacker-controlled domain (prompt-injection scenario documented by the tool itself).
KEV (CISA Known Exploited) No (not listed in CISA KEV at report time).
Default-config reachable Yes — exploitable under both SafeMode on and off; only requires the agent http_request / web_fetch tool to be reachable (default AI tooling).

Appendix: Suggested Patch (F9)

diff --git a/kernel/util/httprequest.go b/kernel/util/httprequest.go
index aaa..bbb 100644
--- a/kernel/util/httprequest.go
+++ b/kernel/util/httprequest.go
@@ -40,6 +40,18 @@ func CheckHostSSRF(host string) error {
 	return nil
 }
 
+// SSRFSafeClient returns an *http.Client whose transport enforces the
+// private/loopback/link-local IP block at CONNECT time (independent of SafeMode),
+// closing the DNS-rebinding TOCTOU left by parse-time-only CheckHostSSRF.
+func SSRFSafeClient(timeout time.Duration) *http.Client {
+	return &http.Client{
+		Timeout: timeout,
+		Transport: &http.Transport{
+			DialContext: util.SSRFSafeDialer(timeout).DialContext,
+		},
+	}
+}
+
 diff --git a/kernel/mcp/tools/http_request.go b/kernel/mcp/tools/http_request.go
 index ccc..ddd 100644
--- a/kernel/mcp/tools/http_request.go
+++ b/kernel/mcp/tools/http_request.go
@@ -90,7 +90,7 @@ func httpRequest(args map[string]any) (CallToolResult, error) {
 	if serr := util.CheckHostSSRF(u.Hostname()); serr != nil {
 		return CallToolResult{}, serr
 	}
-	resp, err := httpclient.NewBrowserRequest().Get(rawURL)
+	resp, err := util.SSRFSafeClient(30 * time.Second).Get(rawURL)
 	...
 }
 diff --git a/kernel/util/webfetch.go b/kernel/util/webfetch.go
 index eee..fff 100644
--- a/kernel/util/webfetch.go
+++ b/kernel/util/webfetch.go
@@ -50,7 +50,7 @@ func WebFetch(rawURL string, ...) (string, error) {
 	if serr := util.CheckHostSSRF(u.Hostname()); serr != nil {
 		return "", serr
 	}
-	resp, err := httpclient.NewBrowserRequest().Get(rawURL)
+	resp, err := util.SSRFSafeClient(30 * time.Second).Get(rawURL)
 	...
 }

Timeline

Published
10 hours ago
October 02, 2026 at 11:17 PM UTC
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC