VYPR

9Router

by 9Router

CVEs (3)

  • CVE-2026-55641HigJul 10, 2026
    risk 0.46cvss 8.2epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default…

  • CVE-2026-62312HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.01

    9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by combining a Host header bypass of localhost-only routes with unvalidated MCP plugin args passed to…

  • CVE-2026-49352CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.01

    9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an…