PatchSiren

shepherd-agents CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW shepherd-agents CVE published 2026-10-11

CVE-2026-108741

A vulnerability in Shepherd through 0.3.1 allows for server-side request forgery (SSRF) via DNS rebinding in the citation checker. This issue arises because the public_url guard validates a resolved address, but the fetch re-resolves the hostname at connect time. Attackers can exploit this by planting a crafted reference URL in a checked document and controlling its DNS, allowing them to rebind it to inte [truncated]