Critical severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover
CVE-2026-55500
Description
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the ALWAYS_PROTECTED middleware check, which only validates JWT or CLI token. This issue is fixed in version 0.4.80.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
9routernpm | <= 0.4.71 | — |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-qvfm-67h2-2qfxghsaADVISORY
- github.com/decolua/9router/commit/0c7c9de00ae3ab81d6580e3cc368483c4c03f6fdmitrex_refsource_MISC
- github.com/decolua/9router/releases/tag/v0.4.80mitrex_refsource_MISC
- github.com/decolua/9router/security/advisories/GHSA-qvfm-67h2-2qfxghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.