CVE-2026-108741
Shepherd through 0.3.1 SSRF via DNS Rebinding in Citation Checker
CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th
Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted reference URL in a checked document and control its DNS can rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files.
| CWE | CWE-367 |
| Vendor | shepherd-agents |
| Product | shepherd |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for shepherd-agents shepherd
Be the first to know when new low vulnerabilities affecting shepherd-agents shepherd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
shepherd-agents / Shepherd
0 โค 0.3.1
References
hackmd.io: https://hackmd.io/@haind03/shepherd-citation-checker-dns-rebinding-ssrf github.com: https://github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/network.py#L9-L17 github.com: https://github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/fetch.py#L34-L55 github.com: https://github.com/shepherd-agents/shepherd vulncheck.com: https://www.vulncheck.com/advisories/shepherd-through-0.3.1-ssrf-via-dns-rebinding-in-citation-checker
Credits
HaiND from the Post and Telecommunication Institute of Technology