{"id":"CVE-2026-67179","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-67179","summary":"Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction…","details":"Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.","published":"2026-08-11T16:17:34.113","modified":"2026-08-11T16:17:34.113","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/genkit-ai/genkit/pull/5587","label":"genkit-ai/genkit#5587"},"references":[{"type":"WEB","url":"https://github.com/genkit-ai/genkit/issues/5581"},{"type":"WEB","url":"https://github.com/genkit-ai/genkit/pull/5587"},{"type":"WEB","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-223-01.json"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-67179"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-11T16:17:34.113"}}