Impact
The vulnerability arises from a TOCTOU race in the http_request and web_fetch agents of SiYuan, which resolve DNS names only at guard time. Attackers can use DNS rebinding to supply a public IP during the guard check and a private or metadata IP at connect time, effectively bypassing the SSRF protection. This flaw enables attackers to reach cloud metadata services or private infrastructure, compromising confidentiality, integrity, and availability of internal data.
Affected Systems
SiYuan software, specifically all releases prior to v3.8.1. The affected product is the SiYuan note application as distributed by Siyuan Note.
Risk and Exploitability
The CVSS score of 8.4 categorizes this flaw as high severity, and the EPSS score is not available, indicating uncertainty about current exploitation frequency. The vulnerability is not yet listed in the CISA KEV catalog. Attackers require the ability to trigger an outbound request from the compromised host to a controlled DNS server; the likely attack vector is an externally accessible network that can influence the DNS responses served by the victim. If exploited, an attacker can read sensitive metadata or access internal services, leading to credential theft or further lateral movement.
OpenCVE Enrichment