Server-Side Request Forgery in SiYuan by SiYuan Team
CVE-2026-82234
8.4HIGH
What is CVE-2026-82234?
SiYuan versions prior to v3.8.1 are susceptible to a server-side request forgery (SSRF) vulnerability stemming from improper validation in the http_request and web_fetch agent tools. This flaw permits attackers to exploit DNS rebinding, which can allow them to manipulate DNS responses at guard time without verification at connect time. Consequently, they can bypass SSRF defenses to gain unauthorized access to sensitive cloud instance metadata and other internal services.
Affected Version(s)
siyuan 0 < 3.8.1
siyuan 3.8.1
