PT-2026-83086 · Siyuan · Siyuan
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.1
Description
Server-side request forgery (SSRF) exists in the
http request and web fetch agent tools. The issue occurs because DNS resolution is performed only during the guard phase without validating the resolution at the time of connection. This allows attackers to use DNS rebinding—a technique where a DNS server changes the IP address associated with a domain name between the initial check and the actual connection—to bypass defenses. By providing a public IP during the guard resolution and a private or metadata IP during the connect resolution, an attacker can access internal services and cloud instance metadata.Recommendations
Update to version 3.8.1.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan