CVE-2026-66005: Permissive List of Allowed Inputs in janhq jan
Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebinding can reach the unauthenticated OpenAI-compatible API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.
AI Analysis
Technical Summary
Jan versions <=0.8.4 contain a Cross-Origin Resource Sharing (CORS) misconfiguration in the local API server. The server replaces user-configured trusted hosts with a wildcard that reflects arbitrary origins and includes credentials, effectively bypassing trusted host restrictions. This allows attackers on the local network or via DNS rebinding to access the unauthenticated OpenAI-compatible API endpoints. Exploitation can lead to unauthorized inference requests, model enumeration, invocation of MCP tools, and reading of cross-origin responses. The vulnerability is addressed in a commit identified as 3e1c1e7, which is after version 0.8.4. No vendor advisory or patch link is currently available to confirm remediation status.
Potential Impact
An attacker on the local network or using DNS rebinding can bypass trusted host restrictions and access the unauthenticated API. This can lead to unauthorized use of inference capabilities, enumeration of available models, invocation of management/control tools (MCP tools), and unauthorized reading of cross-origin responses. The vulnerability exposes sensitive API functionality without authentication, increasing the risk of information disclosure and unauthorized operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability is fixed in a commit after version 0.8.4, upgrading to a version including that fix is recommended once available. Until then, restrict network access to the local API server to trusted hosts only and consider network-level controls to prevent DNS rebinding attacks.
CVE-2026-66005: Permissive List of Allowed Inputs in janhq jan
Description
Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebinding can reach the unauthenticated OpenAI-compatible API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.
CVSS v4.0
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Jan versions <=0.8.4 contain a Cross-Origin Resource Sharing (CORS) misconfiguration in the local API server. The server replaces user-configured trusted hosts with a wildcard that reflects arbitrary origins and includes credentials, effectively bypassing trusted host restrictions. This allows attackers on the local network or via DNS rebinding to access the unauthenticated OpenAI-compatible API endpoints. Exploitation can lead to unauthorized inference requests, model enumeration, invocation of MCP tools, and reading of cross-origin responses. The vulnerability is addressed in a commit identified as 3e1c1e7, which is after version 0.8.4. No vendor advisory or patch link is currently available to confirm remediation status.
Potential Impact
An attacker on the local network or using DNS rebinding can bypass trusted host restrictions and access the unauthenticated API. This can lead to unauthorized use of inference capabilities, enumeration of available models, invocation of management/control tools (MCP tools), and unauthorized reading of cross-origin responses. The vulnerability exposes sensitive API functionality without authentication, increasing the risk of information disclosure and unauthorized operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability is fixed in a commit after version 0.8.4, upgrading to a version including that fix is recommended once available. Until then, restrict network access to the local API server to trusted hosts only and consider network-level controls to prevent DNS rebinding attacks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-23T19:22:30.643Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a637ffa9c2644c7f8203e43
Added to database: 07/24/2026, 15:08:42 UTC
Last enriched: 07/31/2026, 21:13:08 UTC
Last updated: 09/07/2026, 14:05:52 UTC
Views: 99
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.