CVE-2026-67179CWE-644

CVE-2026-67179

High · published August 11, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
3.4
In the wild
Unconfirmed
What it is

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00137 · 3.4th percentile
Weakness
CWE-644 · Improper Neutralization of HTTP Headers for Scripting Syntax
Published
2026-08-11T20:17Z
References (4)
EPSS history
Timeline
  • 11 AUG 15:56Z
    Genkit improper host header validation
    cvelistv5