Jan Local API Server CORS Misconfiguration (CVE-2026-66005)
Jan versions through 0.8.4 contain a CORS misconfiguration vulnerability in the local API server that allows network-adjacent attackers to bypass trusted host restrictions and access the unauthenticated API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.
Disclosed 24 July 2026 · Record updated 13 September 2026
Impact
Network-adjacent attackers can bypass trusted host restrictions and access the local API server to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses without authentication.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-66005
