PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108741 shepherd-agents CVE debrief

A vulnerability in Shepherd through 0.3.1 allows for server-side request forgery (SSRF) via DNS rebinding in the citation checker. This issue arises because the public_url guard validates a resolved address, but the fetch re-resolves the hostname at connect time. Attackers can exploit this by planting a crafted reference URL in a checked document and controlling its DNS, allowing them to rebind it to internal addresses and send GET requests to internal HTTP(S) services, capturing responses in evidence files.

Vendor
shepherd-agents
Product
Shepherd
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Shepherd instances, especially those using version 0.3.1 or earlier, should assess their exposure and consider necessary actions to mitigate the vulnerability.

Why it matters

This vulnerability allows for SSRF via DNS rebinding in the citation checker of Shepherd through 0.3.1. Defenders should verify their instances, consider upgrades, and monitor for suspicious activity.

  • Potential for unauthorized access to internal HTTP(S) services.
  • Possible capture of sensitive information from internal services.
  • Risk of DNS rebinding attacks leading to SSRF.
  • Need for verification of affected versions and remediation.

Technical summary

The vulnerability in Shepherd through 0.3.1 is due to the citation-checker extra's improper handling of DNS rebinding. The public_url guard checks a resolved address, but the fetch operation re-resolves the hostname at connect time. This allows attackers to plant crafted reference URLs in checked documents, control DNS, and rebind to internal addresses, enabling SSRF attacks. Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their Shepherd instances, especially if they are using version 0.3.1 or earlier, and consider upgrading to a patched version if available.

Recommended defensive actions

  • Verify the version of Shepherd being used and assess exposure if using 0.3.1 or earlier.
  • Consider upgrading to a patched version of Shepherd if available.
  • Monitor for suspicious activity related to the citation checker feature.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The evidence for this vulnerability comes from the CVE Program record, the NVD vulnerability detail page, and several source references, including technical descriptions and a third-party advisory. The CVE record was published on 2026-10-11T12:19:45.494Z and has not been modified since then. Shepherd through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted 0

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108741 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108741

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108741 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108741

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Shepherd through 0.3.1 SSRF via DNS Rebinding in Citation Checker

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108741.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind03/shepherd-citation-checker-dns-rebinding-ssrf

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/network.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/fetch.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/shepherd-agents/shepherd

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/shepherd-through-0.3.1-ssrf-via-dns-rebinding-in-citation-checker

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.