CVE-2026-66005: Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that
Summary
Jan (a software tool) versions up to 0.8.4 have a CORS misconfiguration vulnerability (a security flaw where cross-origin requests, which normally have restrictions, are incorrectly allowed) in its local API server. Attackers on the same network can bypass security restrictions by exploiting how the server handles trusted hosts, allowing them to use the API without authentication to run AI tasks, see what models are available, and access responses they shouldn't normally see.
Solution / Mitigation
Fixed in commit 3e1c1e7 (a specific code change in the software's development history).
Vulnerability Details
6.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
network
low
none
required
July 24, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-66005
First tracked: July 24, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%