CVE-2026-108741
Received Received - Intake

Server-Side Request Forgery Bypass in Shepherd AI

Vulnerability report for CVE-2026-108741, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted reference URL in a checked document and control its DNS can rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
shepherd-agents Shepherd 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a server-side request forgery (SSRF) in the Shepherd citation-checker tool through version 0.3.1. It occurs due to a time-of-check time-of-use (TOCTOU) race condition where the public_url guard validates a resolved address but the fetch function re-resolves the hostname at connection time. Attackers can exploit DNS rebinding by planting a crafted reference URL in a document and controlling its DNS to rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files.

Detection Guidance

To detect this vulnerability, monitor network traffic for unexpected outbound connections from the shepherd citation-checker tool. Check logs for DNS rebinding attempts or connections to internal IP addresses. Use tools like tcpdump or Wireshark to capture traffic from the citation-checker process.

Impact Analysis

An attacker could send requests to internal services on your network, potentially accessing sensitive data or services. The attacker needs to control a DNS name with a rebinding record and the victim must run the citation checker with default retrieval enabled. Internal HTTP(S) services on ports 80 or 443 are targeted, and responses are captured in evidence files.

Compliance Impact

This vulnerability could lead to unauthorized access to internal systems, potentially exposing sensitive data. This may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy) by allowing unauthorized data access or disclosure. Organizations using affected versions must address this to maintain regulatory compliance.

Mitigation Strategies

Upgrade shepherd to a version beyond 0.3.1 where the vulnerability is patched. Disable the citation-checker extra if not required. Implement network-level restrictions to block outbound connections to private IP ranges from the citation-checker process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108741. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart