9Router · 9Router · CVE-2026-63732
**Name of the Vulnerable Software and Affected Versions**
9router versions prior to 0.4.60
**Description**
An issue exists involving a chain of security flaws. A hardcoded default password allows authentication on fresh installations. Additionally, the LOCAL ONLY network gate can be bypassed using a spoofed Host header. Furthermore, unvalidated arguments are passed to the `child process.spawn()` function during the registration of MCP plugins. A remote, unauthenticated attacker can exploit these flaws by logging in with the default credential and spoofing the Host header to access local-only routes, subsequently registering a malicious MCP plugin to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.
**Recommendations**
Update to version 0.4.60.