Configuration Injection Vulnerability in 9router by Decolua
CVE-2026-108593
7.3HIGH
What is CVE-2026-108593?
A configuration injection vulnerability exists in the 9router software affecting versions 0.4.1 through 0.5.99. This flaw allows authenticated users to inject arbitrary keys into the Hermes Agent's config.yaml file via the POST /api/cli-tools/hermes-settings endpoint. Attackers can exploit this vulnerability by manipulating the baseUrl to include double quotes and newlines, which can result in the execution of unauthorized commands such as hooks_auto_accept and hooks.post_llm_call, potentially leading to remote command execution without adequate approval after an LLM call.
Affected Version(s)
9router 0.4.1 <= 0.5.99
References
CVSS V4
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
