PatchSiren cyber security CVE debrief
CVE-2026-108741 shepherd-agents CVE debrief
A vulnerability in Shepherd through 0.3.1 allows for server-side request forgery (SSRF) via DNS rebinding in the citation checker. This issue arises because the public_url guard validates a resolved address, but the fetch re-resolves the hostname at connect time. Attackers can exploit this by planting a crafted reference URL in a checked document and controlling its DNS, allowing them to rebind it to internal addresses and send GET requests to internal HTTP(S) services, capturing responses in evidence files.
- Vendor
- shepherd-agents
- Product
- Shepherd
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Shepherd instances, especially those using version 0.3.1 or earlier, should assess their exposure and consider necessary actions to mitigate the vulnerability.
Why it matters
This vulnerability allows for SSRF via DNS rebinding in the citation checker of Shepherd through 0.3.1. Defenders should verify their instances, consider upgrades, and monitor for suspicious activity.
- Potential for unauthorized access to internal HTTP(S) services.
- Possible capture of sensitive information from internal services.
- Risk of DNS rebinding attacks leading to SSRF.
- Need for verification of affected versions and remediation.
Technical summary
The vulnerability in Shepherd through 0.3.1 is due to the citation-checker extra's improper handling of DNS rebinding. The public_url guard checks a resolved address, but the fetch operation re-resolves the hostname at connect time. This allows attackers to plant crafted reference URLs in checked documents, control DNS, and rebind to internal addresses, enabling SSRF attacks. Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their Shepherd instances, especially if they are using version 0.3.1 or earlier, and consider upgrading to a patched version if available.
Recommended defensive actions
- Verify the version of Shepherd being used and assess exposure if using 0.3.1 or earlier.
- Consider upgrading to a patched version of Shepherd if available.
- Monitor for suspicious activity related to the citation checker feature.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The evidence for this vulnerability comes from the CVE Program record, the NVD vulnerability detail page, and several source references, including technical descriptions and a third-party advisory. The CVE record was published on 2026-10-11T12:19:45.494Z and has not been modified since then. Shepherd through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted 0
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108741 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108741
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108741 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108741
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Shepherd through 0.3.1 SSRF via DNS Rebinding in Citation Checker
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108741.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind03/shepherd-citation-checker-dns-rebinding-ssrf
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/network.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/shepherd-agents/shepherd/blob/d34d5ca334871dfcb5a3dc76dd78045829fa4e56/shepherd/extras/citation-checker/src/shepherd_citation_checker/_engine/fetch.py
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/shepherd-agents/shepherd
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/shepherd-through-0.3.1-ssrf-via-dns-rebinding-in-citation-checker
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.