Junglewise Threat Intelligence

CVE-2026-62312: decolua 9Router OS command injection via Host header bypass

CVE-2026-62312 · Severity: high · CVSS 8.8 · Published 2026-07-15

Technologies: Decolua 9router.

Executive brief

9Router, an AI routing and token management tool, contains a security flaw that allows an authenticated user to take full control of the host server. By bypassing internal security checks and providing malicious plugin settings, an attacker can execute arbitrary commands on the operating system. This could lead to the theft of sensitive AI provider API keys, full database access, and the installation of persistent backdoors on the corporate network.

Technical details

A vulnerability chain in 9Router prior to version 0.5.2 allows for remote code execution (RCE). The first flaw is a Host header bypass where the 'isLocalRequest' check in 'src/dashboardGuard.js' incorrectly trusts the client-supplied Host header, allowing remote access to localhost-only routes. The second flaw is an OS command injection vulnerability where MCP plugin arguments are passed unvalidated to 'child_process.spawn()' in 'src/lib/mcp/stdioSseBridge.js'. An authenticated attacker can register a malicious plugin via '/api/cli-tools/cowork-settings' using a spoofed Host header and then trigger execution through the '/api/mcp/<plugin>/sse' endpoint. This allows execution of arbitrary shell commands with the privileges of the 9Router process.

Affected products

  • decolua 9router < 0.5.2

Timeline

  • 2026-06-17: patched: Version 0.5.2 released
  • 2026-07-10: advisory: GitHub Security Advisory GHSA-63p9-g54h-prrp published
  • 2026-07-15: disclosed: CVE-2026-62312 published to NVD

References