CVE-2026-103530High· 7.3▾ TwilightA vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_optio…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-72860High· 8.5The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js
CVE-2026-56676High· 7.49router: Image prefetch DNS rebinding allows SSRF to internal services
CVE-2026-56678Medium· 6.49router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
CVE-2026-56677High· 8.69Router is an AI router & token saver
CVE-2026-56682Medium· 5.39Router is an AI router & token saver
CVE-2026-56681High· 7.39Router is an AI router & token saver