CRITICAL10.0CVE-2026-598019router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats from 0, <= 0.4.41
CRITICAL10.0CVE-2026-463399router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes >= 0.4.30, < 0.4.37
CRITICAL9.9CVE-2026-555009routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover from 0, <= 0.4.71
CRITICAL9.89router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
>= 0.2.21, < 0.4.45
HIGH7.59router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
from 0, <= 0.4.55
HIGH7.39router: Login brute-force protection bypass via spoofed X-Forwarded-For header
from 0, < 0.4.77
HIGH7.3decolua 9router vulnerable to authorization bypass
from 0, < 0.3.75
—9router: Missing Authorization and OS Command Injection
from 0, < 0.4.44