VYPR
High severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026

9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

CVE-2026-49353

Description

9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to protect /api/mcp/*, /api/tunnel/*, and /api/cli-tools/*, allowing header spoofing in reverse proxy or tunnel deployments to reach MCP child process stdin paths.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
9routernpm
<= 0.4.55

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.