Executive brief
Jan is an open-source AI desktop application that provides a local API server for running language models. A security flaw exists where exposing this server to a local network accidentally disables all access restrictions, allowing unauthorized users on the same network to use your AI models or read your data. This could lead to unauthorized use of computing resources or the exposure of sensitive information processed by the AI.
Technical details
A CORS misconfiguration and Host-header bypass exists in Jan's local API server (src-tauri/src/core/server/proxy.rs). When the server is bound to 0.0.0.0, the application logic replaces user-defined 'trusted_hosts' with a wildcard ('*'). This causes the 'is_valid_host' predicate to return true for any origin, leading the server to reflect arbitrary Origins with 'Access-Control-Allow-Credentials: true'. Attackers on the local network or those using DNS rebinding can bypass the unauthenticated OpenAI-compatible API to perform model inference, enumerate models, and read cross-origin responses. The vulnerability is fixed in commit 3e1c1e7 by enforcing the allowlist even when bound to all interfaces.
Affected products
- janhq Jan through 0.8.4
Timeline
- 2026-06-13: disclosed: Vulnerability reported to vendor
- 2026-07-24: patched: Fix merged in commit 3e1c1e7
- 2026-07-24: advisory