CORS Misconfiguration in Jan API Server Affects Local Network Security
CVE-2026-66005

5.3MEDIUM

Key Information:

Vendor

Janhq

Status
Vendor
CVE Published:
24 July 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-66005?

The Jan API Server possesses a CORS misconfiguration that allows network-adjacent attackers to bypass trusted host restrictions via a flaw in the server’s handling of user-configured trusted hosts. This issue enables attackers to manipulate the server, replacing user-defined trusted hosts with a wildcard setting that reflects unauthorized origins and includes credentials. Consequently, attackers on the same local network or those utilizing DNS rebinding techniques can access the OpenAI-compatible API without authentication, leading to potential model enumeration, invocation of MCP tools, and retrieval of cross-origin responses.

Affected Version(s)

jan 0 <= 0.8.4

jan 3e1c1e724f696620d89bb4a9cc18a380e0753757

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.