SCA: security update for 9router (GHSA-g6g7-pvmx-m74p)

critical Tenable Cloud Security Plugin ID 444478

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST
/api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so
no authorization check is applied). The sudoPassword field from the request body is written to the stdin
of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root,
NOPASSWD is configured, or a recent sudo timestamp cache exists), the sudoPassword value is interpreted by
sh as a shell command, allowing a remote unauthenticated attacker to execute arbitrary OS commands.
Exploitation evidence was first observed by the Shadowserver Foundation on 2026-07-04 (UTC).
(CVE-2026-59800)

Solution

Update the 9router library and its related packages to version 0.4.44 or later.

See Also

https://github.com/advisories/GHSA-g6g7-pvmx-m74p

Plugin Details

Severity: Critical

ID: 444478

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 7/7/2026

Updated: 7/8/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.06

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-59800

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 7.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/2/2026

Vulnerability Publication Date: 7/2/2026

Reference Information

CVE: CVE-2026-59800