Security

Reasonix CLI: DNS rebinding to full agent control via serve

Reasonix CLI serve - DNS rebinding defeats the content-type CSRF guard and gives a web page full control of the local agent; file-edit previews read outside the workspace (GHSA-5gf8-hg54-m9q9)

PUBLISHED SEVERITY HIGHSTATUS PatchedGHSA-5gf8-hg54-m9q9
Patched

Fixed in reasonix 1.34.0 (2026-08-30) by maintainer PR #9599, which adds a Host allowlist to serve and confines file-edit previews to the workspace. Track the fix at esengine/DeepSeek-Reasonix#9599.

Product
Reasonix CLI (npm reasonix, 1.x Go line) in esengine/DeepSeek-Reasonix
Affected versions
reasonix (npm, the 1.x Go CLI) before 1.34.0. Fixed in 1.34.0 (2026-08-30). The 2.x Reasonix Studio line is a separate codebase and was not part of this report.
Severity
HIGH
Status
Patched
Weaknesses
  • CWE-350Reliance on Reverse DNS Resolution for a Security-Critical Action
  • CWE-346Origin Validation Error
  • CWE-862Missing Authorization
  • CWE-73External Control of File Name or Path
As filed on the advisory.
GitHub advisory
GHSA-5gf8-hg54-m9q9
Private; closed by the maintainer after the fix, not published
CVE
Pending (requested from MITRE)
Published
Credit
Finder: Aaron Elijah Mars of Aeon. Tool: Aeon (https://www.aeon.fun).

What users should do now

  1. Upgrade the Reasonix CLI to 1.34.0 or later (npm i -g reasonix@latest).
  2. Until you upgrade, do not leave reasonix serve running while you browse, and consider setting serve.auth_mode to token or password.

Summary

reasonix serve runs an unauthenticated local HTTP API (default 127.0.0.1:8787) that drives the coding agent. Before 1.34.0 it checked neither the Host nor the Origin header, and its only cross-site guard was a requirement for Content-Type: application/json. DNS rebinding turns a visited web page into a same-origin client of that API, which removes the guard: the page can switch the session to auto-approve every tool, submit an agent turn (code execution as the user) and read the full transcript. Separately, the write_file, edit_file and multi_edit previews read a model-supplied absolute path without the workspace confinement the other tools apply.

Affected versions

reasonix (npm), the 1.x Go CLI, before 1.34.0, with reasonix serve running in its default configuration (127.0.0.1:8787, serve.auth_mode unset, which means no authentication). The preview issue affects the same versions. The 2.x Reasonix Studio line was not reviewed.

Impact

  • (a) DNS rebinding, high. The application/json requirement stops a plain cross-origin request, because the browser must send a CORS preflight that the server never answers. After DNS rebinding, the attacker's page is same-origin with the local server, so no preflight is needed and responses are readable. The page can then call POST /bypass or POST /tool-approval-mode to auto-approve all tools, POST /submit to run an agent turn whose shell and file tools now run without a human gate, approve pending tool calls, and read /history, /status and the session list.
  • (b) Preview path escape, medium. The previews for write_file, edit_file and multi_edit read the target file with a bare read and skip the confinePreview() check that delete_range and delete_symbol make, so a model-supplied absolute path is read outside the workspace and past the [secrets] protect_sensitive_files denylist.

Browser mitigation. Chrome's Local Network Access prompt raises the bar for (a) when the user denies it. Other browsers were not verified.

Affected code

  • internal/serve/serve.go: handler() wraps the routes as logMiddleware(s.auth.middleware(csrfGuard(mux))), and csrfGuard is the only cross-site check
  • internal/serve/auth.go: the default auth mode none passes every request through
  • internal/cli/cli.go: --addr defaults to 127.0.0.1:8787
  • write_file / edit_file / multi_edit Preview() in internal/tool/builtin/ omit confinePreview()

The fix adds internal/serve/hostguard.go and internal/tool/builtin/confine.go changes in #9599.

Fix

  • #9599 puts a Host allowlist in front of the serve routes (requests with a foreign Host get HTTP 421) and closes the plain-HTTP auth warning gap.
  • The same PR routes the three previews through the workspace confinement boundary.

Detection (for defenders)

Look for requests to the serve port (default 8787) whose Host header names something other than 127.0.0.1, localhost or [::1], and for unexpected POST /bypass, /tool-approval-mode or /submit calls in serve logs. A working exploit is withheld.

Timeline

  1. Reported privately via GitHub PVR (GHSA-5gf8-hg54-m9q9), with suggested fixes.
  2. Maintainer merges #9599 (Host allowlist and preview confinement); reasonix 1.34.0 released the same day.
  3. We confirm the fix covers both findings and note it on the advisory; the maintainer closes the advisory without publishing it.
  4. CVE IDs requested from MITRE.
  5. Public write-up.

Credit

Finder: Aaron Elijah Mars of Aeon. Tool: Aeon.

References