• jan2 vulnerabilities

Showing 2 vulnerabilities on this page for jan

Signals CISA KEV Ransomware Nuclei
janhq vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with credentials. Attackers on the local network or using DNS rebinding can reach the unauthenticated OpenAI-compatible API to perform inference, enumerate models, invoke MCP tools, and read

CWE-183CWE-942Jul 24, 2026
CVSS5.3v4.0EPSS0.187%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jan path traversal vulnerability

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

CWE-22CWE-31Jun 4, 20241 related artifact
CVSS7.5v3.1EPSS2.05%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX