Description
Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted reference URL in a checked document and control its DNS can rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files.
Published: 2026-10-11
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery (SSRF) via DNS rebinding
Action: Assess Impact
AI Analysis

Impact

Shepherd 0.3.1 contains a SSRF weakness in the citation‑checker component. The validator checks the resolved address of a public URL, but the fetch routine re‑resolves the hostname when establishing the connection, allowing a bypass. An attacker who injects a crafted reference URL into a document and controls the DNS mapping for that hostname can cause the server to resolve the hostname to an internal address. The server will then issue a GET request to the internal HTTP(S) service, and the response is captured in evidence files, giving the attacker potential access to internal resources and data.

Affected Systems

The vulnerable product is Shepherd by shepherd‑agents. It is affected by version 0.3.1. No other versions are listed as impacted.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity, and the EPSS score is not available, suggesting limited public exploitation evidence. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker controlling the DNS entry for a hostname supplied to the citation‑checker, a scenario that could be feasible if the system processes untrusted documents. Exploitation would allow internal service access and data exfiltration with no direct impact on the external network, but the internal compromise could still be valuable. The overall risk is low but not negligible for environments that expose the citation‑checker to untrusted input.

Generated by OpenCVE AI on October 11, 2026 at 13:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Consult the Shepherd project for an updated release that addresses the SSRF bug; if no patch is available, remove or disable the citation‑checker extra in the application configuration.
  • Ensure that DNS servers used by the system either reject or do not allow address rebinding for hostnames used by the citation‑checker; alternatively, block internal IP ranges in the resolver configuration.
  • Monitor internal HTTP(S) request logs and evidence file creation for outbound traffic that originates from seemingly legitimate citation checks, to detect potential abuse.

Generated by OpenCVE AI on October 11, 2026 at 13:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted reference URL in a checked document and control its DNS can rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files.
Title Shepherd through 0.3.1 SSRF via DNS Rebinding in Citation Checker
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:45.494Z

Reserved: 2026-10-11T01:52:55.363Z

Link: CVE-2026-108741

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:18.673

Modified: 2026-10-11T13:17:18.673

Link: CVE-2026-108741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:45:03Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition