Low severity3.1NVD Advisory· Published Oct 11, 2026
CVE-2026-108741
CVE-2026-108741
Description
Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted reference URL in a checked document and control its DNS can rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.3.1
Patches
Vulnerability mechanics
References
4- github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/fetch.pynvd
- github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/network.pynvd
- hackmd.io/@haind03/shepherd-citation-checker-dns-rebinding-ssrfnvd
- www.vulncheck.com/advisories/shepherd-through-0.3.1-ssrf-via-dns-rebinding-in-citation-checkernvd
News mentions
0No linked articles in our index yet.