CVE-2026-55638

high

Description

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A remote unauthenticated attacker can send requests to /codex/* to bypass the API-key gate and cause the server to make upstream provider calls using operator-stored LLM provider credentials. This issue is fixed in version 0.5.2.

References

https://github.com/decolua/9router/security/advisories/GHSA-8gmq-j984-vp4r

https://github.com/decolua/9router/releases/tag/v0.5.2

https://github.com/decolua/9router/commit/b282f0554972ea35281520738759d76abcd0b0b3

Details

Source: Mitre, NVD

Published: 2026-07-10

Updated: 2026-07-10

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

Severity: High

CVSS v3

Base Score: 8.6

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Severity: High

EPSS

EPSS: 0.00372