{"data":{"id":"177bd375-363f-4c75-9ab3-5b3a8df4cbaf","title":"CVE-2026-66005: Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that ","summary":"Jan (a software tool) versions up to 0.8.4 have a CORS misconfiguration vulnerability (a security flaw where cross-origin requests, which normally have restrictions, are incorrectly allowed) in its local API server. Attackers on the same network can bypass security restrictions by exploiting how the server handles trusted hosts, allowing them to use the API without authentication to run AI tasks, see what models are available, and access responses they shouldn't normally see.","solution":"Fixed in commit 3e1c1e7 (a specific code change in the software's development history).","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66005","publishedAt":"2026-07-24T15:19:07.203Z","cveId":"CVE-2026-66005","cweIds":["CWE-183","CWE-942"],"cvssScore":"6.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Jan","OpenAI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-24T15:19:07.203Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}