Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-10-02

HighPrimary

SiYuan Agent Tools Could Reach Internal Services Through DNS Rebinding

Analysis of CVE-2026-82234, where SiYuan agent tools could bypass an SSRF check through DNS rebinding and reach internal services.

SiYuanTool execution / MCPDNS-rebinding TOCTOU bypass in agent HTTP toolsSiYuan through version 3.8.0 when the http_request or web_fetch agent tool is reachable

What happened

In a controlled demonstration, SiYuan's http_request and web_fetch agent tools fetched an attacker-controlled hostname that passed the initial public-IP check, then connected to a loopback-only service after the hostname rebound.

Why it matters

Potential disclosure of cloud instance metadata, temporary credentials, or responses from internal services reachable from the SiYuan kernel; the published evidence is a controlled loopback demonstration.

Missing authorization check

A connect-time decision over the exact resolved address class, destination, operation, caller, and expiry before an agent-originated network request is dispatched.

Would PP block it?

The agent could still be steered to request the attacker domain, but a gate that re-evaluates the connect-time address would reject a private, loopback, link-local, or metadata destination lacking explicit authority. Coverage depends on enforcing the gate outside the vulnerable SiYuan request path.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-13

    The researcher reports the DNS-rebinding variant against SiYuan 3.8.0.

  2. 2026-08-13

    The remediation commit later associated with the advisory is recorded in the SiYuan repository.

  3. 2026-10-02

    GitHub publishes GHSA-x8gv-g2g3-65fj and CVE-2026-82234; SiYuan 3.8.1 is identified as patched.

Technical breakdown

  • The agent-controlled URL enters SiYuan through the http_request or web_fetch tool.
  • CheckHostSSRF resolves the hostname once and permits it when the returned address is public.
  • The HTTP transport performs a second DNS lookup without an equivalent connect-time private-address check.
  • The controlled domain returns a loopback address on the second lookup, and the tool reads the loopback-only proof service.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Agent network-tool boundary after final DNS resolution and before connection establishment
Still needs
Permission Protocol does not patch DNS rebinding, make SiYuan's HTTP transport pin DNS results, or protect requests that bypass an independently enforced network boundary. Upgrading SiYuan and enforcing egress controls remain necessary.
Receipt required for
Dispatching an agent-originated HTTP request to the exact resolved destination and address class

A Tool-Call Gate independently enforced at the network dispatch boundary can require authority bound to the canonical destination and connect-time address before the request leaves the runtime.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop