Executive brief
SiYuan is a popular note-taking and knowledge management application with built-in AI agent capabilities that can fetch web content on behalf of the user. A server-side request forgery vulnerability in the http_request and web_fetch agent tools allows attackers to bypass security checks and access cloud instance metadata and internal services on the network. An attacker who can influence the agent to fetch a malicious domain can gain unauthorized access to sensitive internal data and systems.
Technical details
This is a server-side request forgery (CWE-918) vulnerability caused by a time-of-check-to-time-of-use (TOCTOU) issue in DNS resolution. The http_request and web_fetch agent tools perform DNS resolution and validation only at "guard time" using CheckHostSSRF, which blocks private/loopback IP addresses. However, the actual connection phase performs a second, independent DNS resolution via the default net.Dialer without any private IP validation. An attacker can exploit this with DNS rebinding: answer the guard-time resolution with a public IP (bypassing the check) and the connect-time resolution with a private or metadata IP (169.254.169.254), reaching cloud metadata endpoints and internal services. The vulnerability affects all versions up to and including v3.8.0; v3.8.1 contains the fix. Attack requires network access and the ability to influence the agent into fetching an attacker-controlled domain (e.g., via prompt injection).
Affected products
- SiYuan SiYuan before v3.8.1
Timeline
- 2026-08-13: disclosed: Reported to SiYuan team
- 2026-08-28: advisory: CVE-2026-82234 published
- 2026: patched: Fixed in v3.8.1