Sceawere
Vulnerability Detail
CVE-2026-108741UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Shepherd SSRF Guard Bypass
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 4h ago
- Vendor
- shepherd-agents
- Product
- Shepherd
- Attack Type
- Time-of-check Time-of-use (TOCTOU) Race Condition
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted reference URL in a checked document and control its DNS can rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-10-11T13:17:18.673Z",
"pubdate": "2026-10-11T13:17:18.673Z",
"executiveSummary": "Shepherd through 0.3.1 contains a critical Server-Side Request Forgery (SSRF) vulnerability within the citation-checker extra component. The flaw arises from a time-of-check to time-of-use (TOCTOU) race condition during DNS resolution, enabling an attacker to bypass the existing public_url security guard. By leveraging DNS rebinding, an adversary can coerce the application into making HTTP(S) requests to internal resources that were initially blocked by the security filter. The impact of this vulnerability is significant, as it allows unauthorized access to internal services, potentially leading to information disclosure or sensitive data exfiltration. The exploitation requires the attacker to control a malicious DNS server and embed a crafted URL within a document processed by the target system. This vulnerability poses a severe risk to internal network segments that assume protection by boundary-based guards, as the server acts as a proxy for the attacker's requests, capturing and potentially exposing internal service responses via document evidence files.",
"technicalDetails": "The vulnerability resides in the citation-checker extra component of Shepherd (through 0.3.1), specifically where the system validates and fetches external references. The implementation utilizes a public_url guard mechanism designed to perform a security check on the target URL before the fetching process begins. This mechanism resolves the hostname of the provided URL to an IP address, comparing it against a denylist or allowlist to ensure it does not point to restricted internal infrastructure (e.g., local loopback or private IP ranges).\nThe root cause of the flaw is a TOCTOU (Time-of-Check to Time-of-Use) race condition. The vulnerability occurs because the validation logic (the 'check') and the actual connection logic (the 'use') rely on separate DNS resolution processes. The public_url guard resolves the hostname to verify that the target IP address is legitimate; however, the subsequent fetch operation re-resolves the hostname at the time of connection. This separation allows an attacker to manipulate the DNS resolution process to circumvent the guard.\nExploitation follows a specific attack flow: First, an attacker sets up a malicious DNS server configured to serve a short Time-to-Live (TTL) record. The attacker then provides a crafted reference URL, pointing to a domain under their control, within a document submitted to the Shepherd citation-checker. When the guard initiates the validation process, the DNS server responds with a legitimate, external-facing IP address, passing the security check. Immediately following this verification, the citation-checker proceeds to the fetch phase, where the client library performs a fresh DNS query for the same hostname. By this time, the attacker's DNS server updates the record to point to a target internal IP address (e.g., 127.0.0.1 or an internal metadata service).\nBecause the connect logic is decoupled from the initial validation, it inadvertently establishes an HTTP(S) connection to the internal service requested by the attacker. The application then processes the response from the internal service and includes the data in the evidence files generated by the system. This allows the attacker to bypass network-level perimeter security and gain unauthorized interaction with internal web applications, configuration endpoints, or local services, effectively turning the Shepherd instance into a proxy for internal network exploration."
}