๐Ÿ” CVE Alert

CVE-2026-66005

MEDIUM 6.3

Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebinding can reach the unauthenticated OpenAI-compatible API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.

CWE CWE-183 CWE-942
Vendor janhq
Product jan
Published Jul 24, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for janhq jan

Be the first to know when new medium vulnerabilities affecting janhq jan are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

janhq / jan
0 โ‰ค 0.8.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/janhq/jan/issues/8453 github.com: https://github.com/janhq/jan/pull/8506 github.com: https://github.com/janhq/jan/commit/3e1c1e724f696620d89bb4a9cc18a380e0753757 vulncheck.com: https://www.vulncheck.com/advisories/jan-local-api-server-cors-origin-reflection-via-binding

Credits

George Chen