Server-Side Request Forgery Vulnerability in Shepherd by Shepherd Agents
CVE-2026-108741

2.3LOW

Key Information:

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108741?

The Shepherd product, specifically versions up to 0.3.1, is vulnerable to a server-side request forgery (SSRF) due to an oversight in its citation-checker module. The vulnerability arises because the 'public_url' guard only validates a resolved address, allowing an attacker to inject a malicious reference URL into documents. By controlling the DNS resolution, the attacker can redirect requests to internal HTTP(S) services, potentially exposing sensitive data. This exploitation can lead to unauthorized access to internal systems and leakage of responses captured in evidence files. Users of the affected version are advised to apply security patches and review their configurations to mitigate this risk.

Affected Version(s)

Shepherd 0 <= 0.3.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.