VYPR

npm package

9router

pkg:npm/9router

Vulnerabilities (2)

  • CVE-2026-56677HigAug 17, 2026
    affected <= 0.5.4

    9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback destina

  • CVE-2026-5842HigApr 9, 2026
    affected < 0.3.75fixed 0.3.75

    A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely