CVE-2026-56677High· 8.6▾ Twilight9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js with…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback destinations, allowing unauthenticated attackers when dashboard login is disabled to scan internal services and reflect OIDC discovery fields including token_endpoint and jwks_uri.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
9router <= 0.5.4Connected by shared product, vendor, weakness, or advisory.
GHSA-vjc7-jrh9-9j86Critical· 10.09router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
CVE-2026-55638High· 8.69router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVE-2026-59800Critical9router: Missing Authorization and OS Command Injection
CVE-2026-55501High· 7.39router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CVE-2026-55500Critical· 9.99routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
CVE-2026-49352Critical· 9.89router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass