11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether 9router is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-55641
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
HIGH 8.6
CVE-2026-55638
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
HIGH 8.6
CVE-2026-56677
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
CRITICAL 10.0
CVE-2026-59801
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
UNKNOWN
CVE-2026-59800
9router: Missing Authorization and OS Command Injection
HIGH 7.3
CVE-2026-55501
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CRITICAL 9.9
CVE-2026-55500
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
HIGH 7.5
CVE-2026-49353
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CRITICAL 9.8
CVE-2026-49352
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CRITICAL 10.0
CVE-2026-46339
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
HIGH 7.3
CVE-2026-5842
decolua 9router vulnerable to authorization bypass
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes