13 Total advisories
13 Vulnerabilities
0 Malware

Dependency scanning

Check whether 9router is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.3
npm

CVE-2026-56682

9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header

HIGH 7.3
npm

CVE-2026-56681

9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header

HIGH 8.2
npm

CVE-2026-55641

9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF

HIGH 8.6
npm

CVE-2026-55638

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

HIGH 8.6
npm

CVE-2026-56677

9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint

CRITICAL 10.0
npm

CVE-2026-59801

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

UNKNOWN
npm

CVE-2026-59800

9router: Missing Authorization and OS Command Injection

HIGH 7.3
npm

CVE-2026-55501

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

CRITICAL 9.9
npm

CVE-2026-55500

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

HIGH 7.5
npm

CVE-2026-49353

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

CRITICAL 9.8
npm

CVE-2026-49352

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

CRITICAL 10.0
npm

CVE-2026-46339

9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

HIGH 7.3
npm

CVE-2026-5842

decolua 9router vulnerable to authorization bypass

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes