Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-55500: 9routers Exposes Sensitive Data and Database
GHSA-qvfm-67h2-2qfx
CVE-2026-55500
CVE-2026-55500
Summary
The 9routers software exposes sensitive data and allows unauthorized access to its database. This can lead to complete credential theft and database takeover. To protect against this, ensure that you have properly implemented authentication and authorization, and regularly review and update your database settings and credentials.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | decolua | 9router | < 0.4.80 |
| npm | decolua | 9router | <= 0.4.71 |
Original title
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full d...
Original description
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the ALWAYS_PROTECTED middleware check, which only validates JWT or CLI token. This issue is fixed in version 0.4.80.
ghsa CVSS3.1
9.9
Vulnerability type
CWE-200
Information Exposure
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 6 Jul 2026