Reasonix CLI: DNS rebinding to full agent control via serve
Reasonix CLI serve - DNS rebinding defeats the content-type CSRF guard and gives a web page full control of the local agent; file-edit previews read outside the workspace (GHSA-5gf8-hg54-m9q9)
Fixed in reasonix 1.34.0 (2026-08-30) by maintainer PR #9599, which adds a Host allowlist to serve and confines file-edit previews to the workspace. Track the fix at esengine/DeepSeek-Reasonix#9599.
- Product
- Reasonix CLI (npm reasonix, 1.x Go line) in esengine/DeepSeek-Reasonix
- Affected versions
- reasonix (npm, the 1.x Go CLI) before 1.34.0. Fixed in 1.34.0 (2026-08-30). The 2.x Reasonix Studio line is a separate codebase and was not part of this report.
- Severity
- HIGH
- Status
- Patched
- Weaknesses
- CWE-350Reliance on Reverse DNS Resolution for a Security-Critical Action
- CWE-346Origin Validation Error
- CWE-862Missing Authorization
- CWE-73External Control of File Name or Path
- GitHub advisory
- GHSA-5gf8-hg54-m9q9
Private; closed by the maintainer after the fix, not published - CVE
- Pending (requested from MITRE)
- Published
- Credit
- Finder: Aaron Elijah Mars of Aeon. Tool: Aeon (https://www.aeon.fun).
What users should do now
- Upgrade the Reasonix CLI to 1.34.0 or later (
npm i -g reasonix@latest). - Until you upgrade, do not leave
reasonix serverunning while you browse, and consider settingserve.auth_modetotokenorpassword.
Summary
reasonix serve runs an unauthenticated local HTTP API (default 127.0.0.1:8787) that drives the coding agent. Before 1.34.0 it checked neither the Host nor the Origin header, and its only cross-site guard was a requirement for Content-Type: application/json. DNS rebinding turns a visited web page into a same-origin client of that API, which removes the guard: the page can switch the session to auto-approve every tool, submit an agent turn (code execution as the user) and read the full transcript. Separately, the write_file, edit_file and multi_edit previews read a model-supplied absolute path without the workspace confinement the other tools apply.
Affected versions
reasonix (npm), the 1.x Go CLI, before 1.34.0, with reasonix serve running in its default configuration (127.0.0.1:8787, serve.auth_mode unset, which means no authentication). The preview issue affects the same versions. The 2.x Reasonix Studio line was not reviewed.
Impact
- (a) DNS rebinding, high. The
application/jsonrequirement stops a plain cross-origin request, because the browser must send a CORS preflight that the server never answers. After DNS rebinding, the attacker's page is same-origin with the local server, so no preflight is needed and responses are readable. The page can then callPOST /bypassorPOST /tool-approval-modeto auto-approve all tools,POST /submitto run an agent turn whose shell and file tools now run without a human gate, approve pending tool calls, and read/history,/statusand the session list. - (b) Preview path escape, medium. The previews for
write_file,edit_fileandmulti_editread the target file with a bare read and skip theconfinePreview()check thatdelete_rangeanddelete_symbolmake, so a model-supplied absolute path is read outside the workspace and past the[secrets] protect_sensitive_filesdenylist.
Browser mitigation. Chrome's Local Network Access prompt raises the bar for (a) when the user denies it. Other browsers were not verified.
Affected code
internal/serve/serve.go:handler()wraps the routes aslogMiddleware(s.auth.middleware(csrfGuard(mux))), andcsrfGuardis the only cross-site checkinternal/serve/auth.go: the default auth modenonepasses every request throughinternal/cli/cli.go:--addrdefaults to127.0.0.1:8787write_file/edit_file/multi_editPreview()ininternal/tool/builtin/omitconfinePreview()
The fix adds internal/serve/hostguard.go and internal/tool/builtin/confine.go changes in #9599.
Fix
- #9599 puts a
Hostallowlist in front of the serve routes (requests with a foreignHostget HTTP 421) and closes the plain-HTTP auth warning gap. - The same PR routes the three previews through the workspace confinement boundary.
Detection (for defenders)
Look for requests to the serve port (default 8787) whose Host header names something other than 127.0.0.1, localhost or [::1], and for unexpected POST /bypass, /tool-approval-mode or /submit calls in serve logs. A working exploit is withheld.
Timeline
- Reported privately via GitHub PVR (GHSA-5gf8-hg54-m9q9), with suggested fixes.
- Maintainer merges #9599 (Host allowlist and preview confinement); reasonix 1.34.0 released the same day.
- We confirm the fix covers both findings and note it on the advisory; the maintainer closes the advisory without publishing it.
- CVE IDs requested from MITRE.
- Public write-up.
Credit
Finder: Aaron Elijah Mars of Aeon. Tool: Aeon.
References
- Fix PR (merged 2026-08-30): esengine/DeepSeek-Reasonix#9599
- Fixed release: reasonix 1.34.0
- GitHub advisory: GHSA-5gf8-hg54-m9q9 (private; closed, not published)
- CVE: pending (requested from MITRE)
- Affected repository: esengine/DeepSeek-Reasonix