PatchSiren

janhq CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM janhq CVE published 2026-07-24

CVE-2026-66005

CVE-2026-66005 is a medium-severity vulnerability in Jan through version 0.8.4, caused by a CORS misconfiguration in its local API server. This issue allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebind [truncated]