CVE-2026-66005
Published Jul 24, 2026Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host re…
- evidence mentions
- 4
- Buzz score
- 22.6