Remote Code Execution Risk in 9Router AI Router by Decolua
CVE-2026-56681

7.3HIGH

Key Information:

Vendor

Decolua

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-56681?

The 9Router product from Decolua, prior to version 0.5.6, features a vulnerability that allows unauthenticated attackers to exploit the X-9r-Real-Ip header. When improperly configured, this flaw lets attackers masquerade as local clients, potentially bypassing API key validation on sensitive routes. As a result, attackers can consume resources from the router's configured LLM providers, leading to unauthorized use and the risk of credit loss. Users are encouraged to update to version 0.5.6 to mitigate this vulnerability.

Affected Version(s)

9router < 0.5.6

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.