Critical severity9.9NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-55500
CVE-2026-55500
Description
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the ALWAYS_PROTECTED middleware check, which only validates JWT or CLI token. This issue is fixed in version 0.4.80.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
9routernpm | <= 0.4.71 | — |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.