Token Safe AI Router Vulnerability in 9Router by Decolua
CVE-2026-56677
8.6HIGH
What is CVE-2026-56677?
The 9Router software, designed for optimized token saving and management, contains a security flaw in its authentication endpoint. Specifically, the POST /api/auth/oidc/test route does not adequately validate the user-provided issuerUrl parameter, allowing attackers to exploit this oversight when dashboard login is disabled. This improper validation opens avenues for unauthenticated attackers to probe internal services, potentially revealing sensitive OIDC discovery details, such as the token endpoint and JWKS URI, thereby facilitating unauthorized access to critical services.
Affected Version(s)
9router <= 0.5.4
