Junglewise Threat Intelligence

CVE-2026-55638: decolua 9router auth bypass via /codex rewrite

CVE-2026-55638 · Severity: high · CVSS 8.6 · Published 2026-07-10

Technologies: Decolua 9router. Vendors: npm.

Executive brief

9router is a proxy service that provides an OpenAI/Anthropic-compatible LLM (large language model) interface, designed to be protected by API-key authentication. However, a flaw in how the application handles URL rewrites allows unauthenticated attackers to bypass the API-key check by sending requests to the `/codex/*` endpoint instead of the protected `/api/v1/*` endpoint. This allows attackers to use the service operator's credentials to make LLM API calls, consume their provider credits, and incur unexpected billing charges.

Technical details

This is an authorization bypass vulnerability in 9router's Next.js middleware logic. The vulnerability stems from a timing mismatch in the request authorization flow: the middleware in `src/dashboardGuard.js` evaluates whether a request requires an API key based on the original request path before Next.js URL rewrites are applied. The protected prefix list includes `/v1`, `/v1beta`, `/api/v1`, and `/api/v1beta`, but excludes `/codex`. The `next.config.mjs` configuration contains a rewrite rule mapping `/codex/:path*` to `/api/v1/responses`. When an attacker sends a POST request to `/codex/x`, the middleware allows it to pass (because `/codex` is not protected), and the request is then rewritten to `/api/v1/responses` where it is processed by the chat handler using the operator's stored LLM provider API keys. The vulnerability is network-accessible with no authentication required and no user interaction needed. A patch is available in version 0.5.2.

Affected products

  • decolua 9router < 0.5.2

Timeline

  • 2026-07-07: disclosed
  • 2026-07-10: patched: patch released in v0.5.2
  • 2026-08-28: advisory

References

Related threats