What happened
In a controlled demonstration, SiYuan's http_request and web_fetch agent tools fetched an attacker-controlled hostname that passed the initial public-IP check, then connected to a loopback-only service after the hostname rebound.
2026-10-02
HighPrimaryAnalysis of CVE-2026-82234, where SiYuan agent tools could bypass an SSRF check through DNS rebinding and reach internal services.
What happened
In a controlled demonstration, SiYuan's http_request and web_fetch agent tools fetched an attacker-controlled hostname that passed the initial public-IP check, then connected to a loopback-only service after the hostname rebound.
Why it matters
Potential disclosure of cloud instance metadata, temporary credentials, or responses from internal services reachable from the SiYuan kernel; the published evidence is a controlled loopback demonstration.
Missing authorization check
A connect-time decision over the exact resolved address class, destination, operation, caller, and expiry before an agent-originated network request is dispatched.
Would PP block it?
The agent could still be steered to request the attacker domain, but a gate that re-evaluates the connect-time address would reject a private, loopback, link-local, or metadata destination lacking explicit authority. Coverage depends on enforcing the gate outside the vulnerable SiYuan request path.
Incident analysis
2026-08-13
The researcher reports the DNS-rebinding variant against SiYuan 3.8.0.
2026-08-13
The remediation commit later associated with the advisory is recorded in the SiYuan repository.
2026-10-02
GitHub publishes GHSA-x8gv-g2g3-65fj and CVE-2026-82234; SiYuan 3.8.1 is identified as patched.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
A Tool-Call Gate independently enforced at the network dispatch boundary can require authority bound to the canonical destination and connect-time address before the request leaves the runtime.
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.