{"id":"CVE-2026-103530","title":"A vulnerability was detected in decolua 9Router up to 0.5.55","summary":"A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_optio…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-918"],"vendor":"decolua","product":"9Router","affected":["9Router 0.5.0","9Router 0.5.1","9Router 0.5.2","9Router 0.5.3","9Router 0.5.4","9Router 0.5.5","9Router 0.5.6","9Router 0.5.7","9Router 0.5.8","9Router 0.5.9","9Router 0.5.10","9Router 0.5.11","9Router 0.5.12","9Router 0.5.13","9Router 0.5.14","9Router 0.5.15","9Router 0.5.16","9Router 0.5.17","9Router 0.5.18","9Router 0.5.19","9Router 0.5.20","9Router 0.5.21","9Router 0.5.22","9Router 0.5.23","9Router 0.5.24","9Router 0.5.25","9Router 0.5.26","9Router 0.5.27","9Router 0.5.28","9Router 0.5.29","9Router 0.5.30","9Router 0.5.31","9Router 0.5.32","9Router 0.5.33","9Router 0.5.34","9Router 0.5.35","9Router 0.5.36","9Router 0.5.37","9Router 0.5.38","9Router 0.5.39","9Router 0.5.40","9Router 0.5.41","9Router 0.5.42","9Router 0.5.43","9Router 0.5.44","9Router 0.5.45","9Router 0.5.46","9Router 0.5.47","9Router 0.5.48","9Router 0.5.49"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T00:16:44.563","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103530","references":[{"url":"https://github.com/decolua/9router/","label":"cna@vuldb.com"},{"url":"https://github.com/decolua/9router/issues/3714","label":"cna@vuldb.com"},{"url":"https://github.com/decolua/9router/pull/3723","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-103530","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/956865","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/412342","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/412342/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T00:33:27.736Z","slug":"CVE-2026-103530","body":"## Overview\n\nA vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}