{"id":"CVE-2026-55500","aliases":["GHSA-qvfm-67h2-2qfx"],"title":"9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover","summary":"9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover","severity":"critical","cvss":9.9,"cwe":["CWE-200"],"vendor":"9router","product":"9router","ecosystem":"npm","affected":["9router <= 0.4.71"],"published":"2026-07-06","updated":"2026-07-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-qvfm-67h2-2qfx","references":[{"url":"https://github.com/decolua/9router/security/advisories/GHSA-qvfm-67h2-2qfx"},{"url":"https://github.com/advisories/GHSA-qvfm-67h2-2qfx"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-06T21:45:52.873Z","epss":0.00685,"epssPercentile":0.50767,"slug":"CVE-2026-55500","body":"## Overview\n\n## Summary\n\nThe `/api/settings/database` endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the `ALWAYS_PROTECTED` middleware check, which only validates JWT or CLI token. Combined with other vulnerabilities (e.g., default password, tunnel exposure), this enables complete database takeover.\n\n## Description\n\nThe endpoint `/api/settings/database` is listed in `ALWAYS_PROTECTED` in `dashboardGuard.js` (line 42), which requires a valid JWT token or CLI token. However, this protection is insufficient because:\n\n1. **GET (Export):** Returns the complete database including API keys (`key` field in `apiKeys` table), OAuth tokens, and all provider credentials. Line 80 in `src/lib/db/index.js`: `apiKeys: db.all(\"SELECT * FROM apiKeys\").map(...)` — the `key` field contains the plaintext API key value.\n\n2. **POST (Import):** Accepts arbitrary JSON and performs a complete database wipe-and-replace in a transaction (lines 102-163 in `src/lib/db/index.js`). This replaces all settings including the password hash, effectively allowing an attacker to set their own password.\n\n3. The exported data includes `apiKeys` with their plaintext `key` values, `providerConnections` with all OAuth tokens, and `settings` with OIDC client secrets.\n\n### Evidence\n\n**File:** `src/app/api/settings/database/route.js`\n```javascript\nexport async function GET() {\n  const payload = await exportDb();\n  return NextResponse.json(payload);\n}\n\nexport async function POST(request) {\n  const payload = await request.json();\n  await importDb(payload);\n  // ...\n}\n```\n\n**File:** `src/lib/db/index.js` (lines 96-163)\n```javascript\nexport async function importDb(payload) {\n  db.transaction(() => {\n    // Wipe all tables\n    db.run(`DELETE FROM settings`);\n    db.run(`DELETE FROM providerConnections`);\n    db.run(`DELETE FROM providerNodes`);\n    db.run(`DELETE FROM proxyPools`);\n    db.run(`DELETE FROM apiKeys`);\n    db.run(`DELETE FROM combos`);\n    db.run(`DELETE FROM kv WHERE scope IN (...)`);\n    // Then insert attacker-controlled data\n    // ...\n  });\n}\n```\n\nThe `exportDb` function at line 80 exposes API key plaintext:\n```javascript\napiKeys: db.all(`SELECT * FROM apiKeys`).map((r) => ({ \n  id: r.id, key: r.key, name: r.name, ...\n})),\n```\n\n## Steps to Reproduce\n\n1. Authenticate with any valid JWT (e.g., using the default password \"123456\")\n2. Export: `curl -b auth_token=<jwt> http://localhost:20128/api/settings/database`\n3. Observe: Full database dump with all credentials in plaintext\n4. Import malicious data: `curl -X POST -b auth_token=<jwt> -H \"Content-Type: application/json\" -d '<modified-db>' http://localhost:20128/api/settings/database`\n5. All settings, passwords, API keys are now replaced with attacker-controlled values\n\n## Impact\n\n- **Confidentiality:** Complete exposure of all stored secrets (API keys, OAuth tokens, OIDC client secrets)\n- **Integrity:** Complete database replacement with attacker-controlled data\n- **Availability:** Database wipe is possible by importing an empty database\n- **Scope Changed:** Importing new settings affects all users and downstream services\n\n## Recommended Fix\n\n1. Require re-authentication for database export/import (not just an existing session)\n2. Mask/redact API keys in export (or require explicit opt-in for key export)\n3. Add confirmation step for import (require current password verification)\n4. Implement database backup before import\n5. Log all export/import operations with audit trail\n\n## Affected packages\n\n- `9router <= 0.4.71`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":54.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}