CVE-2026-67179
HIGH
7,8
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.
644
Improper Neutralization of HTTP Headers for Scripting Syntax
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Read Application Data
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/genkit-ai/genkit/issues/5581
https://github.com/genkit-ai/genkit/pull/5587
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026…
https://www.cve.org/CVERecord?id=CVE-2026-67179