Request Header Validation Flaw in Genkit by Genkit AI
CVE-2026-67179

7.8HIGH

Key Information:

Vendor

Genkit-ai

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-67179?

Genkit, developed by Genkit AI, contains a security flaw where it fails to properly validate host request headers. This vulnerability allows any host on the developer's network, as well as websites visited by the developer, to potentially interact with the Genkit API (located at /api/runAction on the default port 4000). As a result, an attacker could execute any registered actions within the Genkit application and access the results. This issue was addressed on June 18, 2026, to enhance security and prevent unauthorized access.

Affected Version(s)

genkit 0 < 2026-06-18

genkit 2026-06-18

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.