Executive brief
decolua 9router is an AI routing tool used to connect various AI coding assistants to different model providers. A critical security flaw allows unauthenticated attackers to bypass security controls and access administrative functions. This could result in the theft of sensitive API keys, exposure of the entire application database, or a complete shutdown of the service.
Technical details
A critical broken access control vulnerability exists in 9router due to improper middleware configuration. While authentication is enforced for the dashboard UI, the '/api/*' routes were excluded from the global authentication matcher. This allows unauthenticated remote attackers to directly interact with sensitive endpoints such as '/api/settings/database', '/api/keys', and '/api/shutdown'. Successful exploitation enables attackers to export or overwrite the database, retrieve provider credentials, generate new API keys, or perform a remote denial-of-service by shutting down the server. The issue is resolved in version 0.3.75.
Affected products
- decolua 9router < 0.3.75
Timeline
- 2026-03-26: disclosed: Initial issue reported on GitHub
- 2026-04-09: advisory: GitHub and NVD advisories published
- 2026-04-09: patched: Version 0.3.75 released to address the vulnerability