CVE-2026-67179: CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax in genkit-ai genkit
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.
AI Analysis
Technical Summary
Genkit does not properly validate host request headers, leading to a CWE-644 vulnerability (Improper Neutralization of HTTP Headers for Scripting Syntax). This flaw allows any host within the developer's network or any website the developer visits, through DNS rebinding, to reach the POST /api/runAction endpoint on the Dev UI server (default port 4000). Attackers can execute any registered Genkit action and read the results. The vulnerability has a CVSS 3.1 score of 7.8, indicating high impact on confidentiality, integrity, and availability. The issue was fixed on 2026-06-18, though no explicit patch or remediation link is provided in the data.
Potential Impact
Successful exploitation allows an attacker on the developer's network or a malicious website visited by the developer to execute arbitrary registered actions on the Genkit Dev UI server and read their results. This compromises confidentiality, integrity, and availability of the affected system components.
Mitigation Recommendations
The vulnerability was fixed on 2026-06-18. Although no explicit patch link is provided, users should update to the fixed version released after this date. Since this is not a cloud service, remediation requires applying the vendor's fix. Check the vendor advisory for the exact fixed version and update instructions.
CVE-2026-67179: CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax in genkit-ai genkit
Description
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.
CVSS v3.1
Score 7.8high
Affected software
genkit-ai
genkit
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Genkit does not properly validate host request headers, leading to a CWE-644 vulnerability (Improper Neutralization of HTTP Headers for Scripting Syntax). This flaw allows any host within the developer's network or any website the developer visits, through DNS rebinding, to reach the POST /api/runAction endpoint on the Dev UI server (default port 4000). Attackers can execute any registered Genkit action and read the results. The vulnerability has a CVSS 3.1 score of 7.8, indicating high impact on confidentiality, integrity, and availability. The issue was fixed on 2026-06-18, though no explicit patch or remediation link is provided in the data.
Potential Impact
Successful exploitation allows an attacker on the developer's network or a malicious website visited by the developer to execute arbitrary registered actions on the Genkit Dev UI server and read their results. This compromises confidentiality, integrity, and availability of the affected system components.
Mitigation Recommendations
The vulnerability was fixed on 2026-06-18. Although no explicit patch link is provided, users should update to the fixed version released after this date. Since this is not a cloud service, remediation requires applying the vendor's fix. Check the vendor advisory for the exact fixed version and update instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisa-cg
- Date Reserved
- 2026-07-28T14:53:02.567Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7b49e7bf8831d53902c3cb
Added to database: 08/11/2026, 16:12:23 UTC
Last enriched: 08/11/2026, 16:26:24 UTC
Last updated: 09/25/2026, 13:47:47 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.