Executive brief
9Router, an AI routing and token management tool, contains a security flaw that allows unauthorized users to bypass authentication when the software is used behind a standard reverse proxy like Nginx. Because the router incorrectly trusts all traffic coming from the local proxy as 'safe,' an attacker can access the system's AI models and APIs without a valid key. This could allow unauthorized parties to use the owner's paid AI service credentials, leading to unexpected costs and data exposure.
Technical details
9Router (prior to version 0.5.2) contains an authentication bypass vulnerability in its 'dashboardGuard.js' component. The application incorrectly assumes that any request originating from the loopback address (127.0.0.1) is a trusted local request and does not require an API key for /v1/* endpoints. When deployed behind a reverse proxy (such as Nginx) on the same host, all external traffic is forwarded via the loopback interface, causing the application to misclassify remote requests as local. An unauthenticated remote attacker can exploit this to access sensitive endpoints like /v1/models and /v1/chat/completions, potentially exhausting the operator's upstream AI provider quotas. The fix, introduced in v0.5.2, involves checking for forwarding headers (X-Forwarded-For/X-Real-IP) to ensure proxy hops are not treated as trusted local users.
Affected products
- decolua 9router < 0.5.2
Timeline
- 2026-06-17: patched: Version 0.5.2 released
- 2026-07-07: advisory: GitHub Security Advisory published
- 2026-07-10: disclosed: CVE published to NVD