CVE-2026-67179EPSS p7.5%
CVE-2026-67179CVE-2026-67179
Description
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.19% probability of exploitation · percentile 7.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-26 |