What is CVE-2026-66005?
CVE-2026-66005 is a CORS misconfiguration vulnerability in Jan versions up to 0.8.4, affecting its local API server. It allows network-adjacent attackers to bypass trusted host restrictions by exploiting a wildcard replacement of user-configured hosts. Update to the version containing commit 3e1c1e7 to remediate this issue.
Azərbaycanca: CVE-2026-66005, Jan tətbiqinin 0.8.4-ə qədər versiyalarında lokal API serverində CORS yanlış konfiqurasiya zəifliyidir. Bu, şəbəkə səviyyəsində yaxın olan hücumçulara istifadəçi tərəfindən təyin edilmiş etibarlı host məhdudiyyətlərini keçərək icazəsiz əməliyyatlar aparmağa imkan verir. Təhlükəsizlik üçün commit 3e1c1e7 ilə təqdim edilən düzəliş tətbiq edilməlidir.
FAQ2
What kind of access does an attacker exploiting CVE-2026-66005 gain?
Network-adjacent attackers can bypass user-configured trusted host restrictions to perform unauthorized operations on the local API server.
What step should be taken to remediate CVE-2026-66005?
Update to the version containing the security fix introduced with commit 3e1c1e7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.