Impact
Shepherd 0.3.1 contains a SSRF weakness in the citation‑checker component. The validator checks the resolved address of a public URL, but the fetch routine re‑resolves the hostname when establishing the connection, allowing a bypass. An attacker who injects a crafted reference URL into a document and controls the DNS mapping for that hostname can cause the server to resolve the hostname to an internal address. The server will then issue a GET request to the internal HTTP(S) service, and the response is captured in evidence files, giving the attacker potential access to internal resources and data.
Affected Systems
The vulnerable product is Shepherd by shepherd‑agents. It is affected by version 0.3.1. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score is not available, suggesting limited public exploitation evidence. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker controlling the DNS entry for a hostname supplied to the citation‑checker, a scenario that could be feasible if the system processes untrusted documents. Exploitation would allow internal service access and data exfiltration with no direct impact on the external network, but the internal compromise could still be valuable. The overall risk is low but not negligible for environments that expose the citation‑checker to untrusted input.
OpenCVE Enrichment