MEDIUM
janhq
CVE published 2026-07-24
CVE-2026-66005
CVE-2026-66005 is a medium-severity vulnerability in Jan through version 0.8.4, caused by a CORS misconfiguration in its local API server. This issue allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebind [truncated]