Technology · npm
9router (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 26 vulnerabilities in 9router (npm): 2 in the last 7 days and 24 in the last 90 days, 9 of them critical and 0 exploited in the wild. The most recent, CVE-2026-56682, was published on 22 September 2026.
- Last 7 days
- 2
- Last 90 days
- 24
- Critical, all time
- 9
- Exploited in the wild
- 0
About 9router (npm)
A routing library for Node.js applications.
Latest 9router (npm) vulnerabilities
- CVE-2026-56682: 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without…mediumCVSS 5.3EPSS 0.5%
- CVE-2026-56681: 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without…highCVSS 7.3EPSS 1.0%
- CVE-2026-72860: 9router SSRF via WHATWG IPv6 canonicalization in /api/provider-nodes/validatehighCVSS 8.5EPSS 0.4%
- CVE-2026-56677: 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in…highCVSS 8.6EPSS 0.4%
- CVE-2026-63732: decolua 9router remote code execution via vulnerability chaincriticalCVSS 9.9
- CVE-2026-63313: decolua 9Router SSRF in /v1/web/fetch endpointhighCVSS 7.7
- CVE-2026-62312: decolua 9Router OS command injection via Host header bypasshighCVSS 8.8
- CVE-2026-56679: decolua 9Router mass assignment in /api/settingshighCVSS 4EPSS 0.5%
- CVE-2026-56678: decolua 9router SSRF and credential forwarding in Kiro API validationmediumCVSS 6.4EPSS 0.3%
- CVE-2026-49353: decolua 9router authentication bypass via Host header spoofinghighCVSS 7.5EPSS 0.4%
- CVE-2026-49352: decolua 9Router authentication bypass via hardcoded JWT secretcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-46339: decolua 9router unauthenticated RCE via MCP custom pluginscriticalCVSS 10EPSS 3.4%
- CVE-2026-62328: decolua 9Router missing authentication in API endpointshighCVSS 7.5
- CVE-2026-62327: decolua 9Router missing authentication in API endpointscriticalCVSS 9.1
- CVE-2026-59801: decolua 9Router missing authentication in management APIcriticalCVSS 9.8EPSS 2.9%
- CVE-2026-56675: decolua 9Router authentication bypass via loopback trust collapsehighCVSS 8.3EPSS 0.5%
- CVE-2026-55641: decolua 9router auth bypass and SSRF via Host header spoofinghighCVSS 8.2EPSS 0.3%
- CVE-2026-55638: decolua 9router auth bypass via /codex rewritehighCVSS 8.6EPSS 0.6%
- CVE-2026-56676: decolua 9router SSRF via DNS rebinding in image prefetchhighCVSS 7.4EPSS 0.3%
- CVE-2026-55501: Decolua 9Router login rate limit bypass via X-Forwarded-For spoofinghighCVSS 7.3EPSS 0.5%
- CVE-2026-55500: decolua 9Router authentication bypass in database export and importcriticalCVSS 9.9EPSS 0.7%
- CVE-2026-59800: decolua 9Router OS command injection in tailscale-install endpointcriticalCVSS 9.8EPSS 2.0%
- Decolua 9Router multiple authentication bypasses and sensitive data leakscriticalCVSS 10
- 9router unauthenticated RCE via command injection in Tailscale installationcriticalCVSS 9.2
- CVE-2026-10269: decolua 9router improper authorization in dashboardGuard.jsmediumCVSS 6.3
Most severe 9router (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-46339: decolua 9router unauthenticated RCE via MCP custom pluginscriticalCVSS 10EPSS 3.4%
- Decolua 9Router multiple authentication bypasses and sensitive data leakscriticalCVSS 10
- CVE-2026-55500: decolua 9Router authentication bypass in database export and importcriticalCVSS 9.9EPSS 0.7%
- CVE-2026-63732: decolua 9router remote code execution via vulnerability chaincriticalCVSS 9.9
- CVE-2026-59801: decolua 9Router missing authentication in management APIcriticalCVSS 9.8EPSS 2.9%
- CVE-2026-59800: decolua 9Router OS command injection in tailscale-install endpointcriticalCVSS 9.8EPSS 2.0%
- CVE-2026-49352: decolua 9Router authentication bypass via hardcoded JWT secretcriticalCVSS 9.8EPSS 0.6%
- 9router unauthenticated RCE via command injection in Tailscale installationcriticalCVSS 9.2
- CVE-2026-62327: decolua 9Router missing authentication in API endpointscriticalCVSS 9.1
- CVE-2026-62312: decolua 9Router OS command injection via Host header bypasshighCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 1 | |
| 6 Jul 2026 | 8 | 3 | |
| 13 Jul 2026 | 9 | 4 | |
| 20 Jul 2026 | 2 | 1 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 2 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/9router.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "9router (npm) vulnerabilities", https://junglewise.ai/threats/technologies/9router, 26 September 2026.