Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
npm/9router — 8 CVEs · VulnScope
pkg:npm/
9router
8 total CVEs
CRITICAL
4
HIGH
3
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
10.0
CVE-2026-59801
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
from 0, <= 0.4.41
CRITICAL
10.0
CVE-2026-46339
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
>= 0.4.30, < 0.4.37
CRITICAL
9.9
CVE-2026-55500
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
from 0, <= 0.4.71
CRITICAL
9.8
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
>= 0.2.21, < 0.4.45
HIGH
7.5
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
from 0, <= 0.4.55
HIGH
7.3
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
from 0, < 0.4.77
HIGH
7.3
decolua 9router vulnerable to authorization bypass
from 0, < 0.3.75
—
9router: Missing Authorization and OS Command Injection
from 0, < 0.4.44
CVE-2026-49352
CVE-2026-49353
CVE-2026-55501
CVE-2026-5842
CVE-2026-59800