9router has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 7. The median CVSS is 8.6 (high), with 5 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-862 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.6
- Publish → KEV
- —
- Last 90 days
- 9 prev 0
Worst active — by depth score
CVE-2026-49352Critical· 9.89router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass66GHSA-vjc7-jrh9-9j86Critical· 10.09router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats55CVE-2026-55500Critical· 9.99routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover55CVE-2026-59800Critical9router: Missing Authorization and OS Command Injection53GHSA-g6g7-pvmx-m74pCritical9router: Missing Authorization and OS Command Injection52
9router vulnerabilities
CVEs affecting 9router, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
CVE-2026-55638High· 8.69router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVE-2026-56677High· 8.69Router is an AI router & token saver
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js with…
CVE-2026-55501High· 7.39router: Login brute-force protection bypass via spoofed X-Forwarded-For header
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
GHSA-vjc7-jrh9-9j86Critical· 10.09router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
CVE-2026-55500Critical· 9.99routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
CVE-2026-59800Critical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
CVE-2026-49352Critical· 9.8PoC9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVE-2026-49353High· 7.59router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
GHSA-g6g7-pvmx-m74pCritical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection