Back to overview

CVE-2026-66005

MEDIUM Exploitation: PoC
6.3
CVSS 3.1
Description
Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebinding can reach the unauthenticated OpenAI-compatible API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.

Metadata

CVE ID
CVE-2026-66005
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-23 19:22 UTC
Published
2026-07-24 14:57 UTC
Last updated
2026-07-24 15:32 UTC
Primary CWE
CWE-183
Permissive List of Allowed Inputs
Vendor / Product
janhq / jan
Sources
cve.org  ·  NVD

Severity & Metrics

6.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
janhq jan 0 ≤ 0.8.4, 3e1c1e724f696620d89bb4a9cc18a380e0753757
Weakness (CWE)
CWESourceDescription
CWE-183 cna Permissive List of Allowed Inputs
CWE-942 cna Permissive Cross-domain Security Policy with Untrusted Domains
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Back to overview