Configuration Injection Vulnerability in 9router by Decolua
CVE-2026-108593

7.3HIGH

Key Information:

Vendor

Decolua

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108593?

A configuration injection vulnerability exists in the 9router software affecting versions 0.4.1 through 0.5.99. This flaw allows authenticated users to inject arbitrary keys into the Hermes Agent's config.yaml file via the POST /api/cli-tools/hermes-settings endpoint. Attackers can exploit this vulnerability by manipulating the baseUrl to include double quotes and newlines, which can result in the execution of unauthorized commands such as hooks_auto_accept and hooks.post_llm_call, potentially leading to remote command execution without adequate approval after an LLM call.

Affected Version(s)

9router 0.4.1 <= 0.5.99

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.