PT-2026-64318 · Git+1 · Jan
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Jan versions prior to 0.8.4
Description
A CORS (Cross-Origin Resource Sharing) misconfiguration in the local API server allows network-adjacent attackers to bypass trusted host restrictions. This occurs because the server replaces user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or those using DNS rebinding—a technique that tricks a browser into thinking a malicious site is a trusted one—can access the unauthenticated OpenAI-compatible API to perform inference, enumerate models, invoke MCP tools, and read cross-origin responses.
Recommendations
Update Jan to a version that includes the fix implemented in commit 3e1c1e7.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jan