---
id: CVE-2026-103530
title: A vulnerability was detected in decolua 9Router up to 0.5.55
summary: >-
  A vulnerability was detected in decolua 9Router up to 0.5.55. The affected
  element is the function fetch of the file src/shared/utils/ssrfGuard.js of the
  component Search Endpoint. Performing a manipulation of the argument
  provider_optio…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-918
vendor: decolua
product: 9Router
affected:
  - 9Router 0.5.0
  - 9Router 0.5.1
  - 9Router 0.5.2
  - 9Router 0.5.3
  - 9Router 0.5.4
  - 9Router 0.5.5
  - 9Router 0.5.6
  - 9Router 0.5.7
  - 9Router 0.5.8
  - 9Router 0.5.9
  - 9Router 0.5.10
  - 9Router 0.5.11
  - 9Router 0.5.12
  - 9Router 0.5.13
  - 9Router 0.5.14
  - 9Router 0.5.15
  - 9Router 0.5.16
  - 9Router 0.5.17
  - 9Router 0.5.18
  - 9Router 0.5.19
  - 9Router 0.5.20
  - 9Router 0.5.21
  - 9Router 0.5.22
  - 9Router 0.5.23
  - 9Router 0.5.24
  - 9Router 0.5.25
  - 9Router 0.5.26
  - 9Router 0.5.27
  - 9Router 0.5.28
  - 9Router 0.5.29
  - 9Router 0.5.30
  - 9Router 0.5.31
  - 9Router 0.5.32
  - 9Router 0.5.33
  - 9Router 0.5.34
  - 9Router 0.5.35
  - 9Router 0.5.36
  - 9Router 0.5.37
  - 9Router 0.5.38
  - 9Router 0.5.39
  - 9Router 0.5.40
  - 9Router 0.5.41
  - 9Router 0.5.42
  - 9Router 0.5.43
  - 9Router 0.5.44
  - 9Router 0.5.45
  - 9Router 0.5.46
  - 9Router 0.5.47
  - 9Router 0.5.48
  - 9Router 0.5.49
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T00:16:44.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103530'
references:
  - url: 'https://github.com/decolua/9router/'
    label: cna@vuldb.com
  - url: 'https://github.com/decolua/9router/issues/3714'
    label: cna@vuldb.com
  - url: 'https://github.com/decolua/9router/pull/3723'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-103530'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/956865'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/412342'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/412342/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T00:33:27.736Z'
---

## Overview

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
