CORS Misconfiguration in Jan API Server Affects Local Network Security
CVE-2026-66005
Key Information:
Badges
What is CVE-2026-66005?
The Jan API Server possesses a CORS misconfiguration that allows network-adjacent attackers to bypass trusted host restrictions via a flaw in the server’s handling of user-configured trusted hosts. This issue enables attackers to manipulate the server, replacing user-defined trusted hosts with a wildcard setting that reflects unauthorized origins and includes credentials. Consequently, attackers on the same local network or those utilizing DNS rebinding techniques can access the OpenAI-compatible API without authentication, leading to potential model enumeration, invocation of MCP tools, and retrieval of cross-origin responses.
Affected Version(s)
jan 0 <= 0.8.4
jan 3e1c1e724f696620d89bb4a9cc18a380e0753757
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
