Remote Code Execution Risk in 9Router AI Router by Decolua
CVE-2026-56681
7.3HIGH
What is CVE-2026-56681?
The 9Router product from Decolua, prior to version 0.5.6, features a vulnerability that allows unauthenticated attackers to exploit the X-9r-Real-Ip header. When improperly configured, this flaw lets attackers masquerade as local clients, potentially bypassing API key validation on sensitive routes. As a result, attackers can consume resources from the router's configured LLM providers, leading to unauthorized use and the risk of credit loss. Users are encouraged to update to version 0.5.6 to mitigate this vulnerability.
Affected Version(s)
9router < 0.5.6
