Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Darealdanh

#25294of 56,330
9.9Total CVSS
Vulnerabilities · 1
PT-2026-64186
9.9
2026-07-23
9Router · 9Router · CVE-2026-63732
**Name of the Vulnerable Software and Affected Versions** 9router versions prior to 0.4.60 **Description** An issue exists involving a chain of security flaws. A hardcoded default password allows authentication on fresh installations. Additionally, the LOCAL ONLY network gate can be bypassed using a spoofed Host header. Furthermore, unvalidated arguments are passed to the `child process.spawn()` function during the registration of MCP plugins. A remote, unauthenticated attacker can exploit these flaws by logging in with the default credential and spoofing the Host header to access local-only routes, subsequently registering a malicious MCP plugin to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered. **Recommendations** Update to version 0.4.60.