VulnSea

9Router vulnerabilities

CVEs whose affected-version data names the 9Router package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

17 CVEsRSS

CVE-2026-103530High· 7.3
today

A vulnerability was detected in decolua 9Router up to 0.5.55

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_optio…

▾ Twilightdecolua · 9Routervia NVD
CVE-2026-56675High· 8.3
1w ago

9router /v1 APIs has unauthenticated access via reverse proxy locality collapse

9router /v1 APIs has unauthenticated access via reverse proxy locality collapse

▾ Twilight9router · 9routerEPSS 0.50%via GHSA
CVE-2026-56679High
1w ago

9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade

9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade

▾ Twilight9router · 9routerEPSS 0.52%via GHSA
CVE-2026-56678Medium· 6.4
1w ago

9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding

9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding

▾ Sunlit9router · 9routerEPSS 0.29%via GHSA
CVE-2026-56676High· 7.4
1w ago

9router: Image prefetch DNS rebinding allows SSRF to internal services

9router: Image prefetch DNS rebinding allows SSRF to internal services

▾ Twilight9router · 9routerEPSS 0.26%via GHSA
CVE-2026-56682Medium· 5.3PoC
1w ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, …

▾ Twilightdecolua · 9routerEPSS 0.47%via NVD
CVE-2026-56681High· 7.3PoC
1w ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when i…

▾ Midnightdecolua · 9routerEPSS 0.97%via NVD
CVE-2026-55638High· 8.6
1mo ago

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

▾ Twilight9router · 9routerEPSS 0.61%via GHSA
CVE-2026-72860High· 8.5PoC
1mo ago

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares host…

▾ Midnightdecolua · 9routerEPSS 0.38%via NVD
CVE-2026-56677High· 8.6
1mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js with…

▾ Twilight9router · 9routerEPSS 0.38%via NVD
CVE-2026-55501High· 7.3
2mo ago

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

▾ Twilight9router · 9routerEPSS 0.52%via GHSA
GHSA-vjc7-jrh9-9j86Critical· 10.0
2mo ago

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

▾ Midnight9router · 9routervia GHSA
CVE-2026-55500Critical· 9.9
2mo ago

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

▾ Midnight9router · 9routerEPSS 0.69%via GHSA
CVE-2026-59800Critical
3mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routerEPSS 2.0%via GHSA
CVE-2026-49352Critical· 9.8PoC
3mo ago

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

▾ Abyssal9router · 9routerEPSS 0.60%via GHSA
CVE-2026-49353High· 7.5
3mo ago

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

▾ Twilight9router · 9routerEPSS 0.36%via GHSA
GHSA-g6g7-pvmx-m74pCritical
3mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routervia GHSA
9Router vulnerabilities (CVEs) · VulnSea