PT-2026-57907 · 9Router · 9Router

CVE-2026-62328

·

Published

2026-07-06

·

Updated

2026-07-13

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 9Router versions prior to 0.4.42
Description An unauthenticated information disclosure issue allows remote attackers to access sensitive user data. By querying the 'request-logs' and 'request-details' API endpoints, which lack authentication middleware, attackers can enumerate paginated request logs and retrieve complete AI conversation histories. This exposed data includes system prompts, user messages, assistant responses, tool calls, and user email addresses.
Recommendations Update 9Router to version 0.4.42 or later. Restrict access to the 'request-logs' and 'request-details' API endpoints until the update is applied.

Exploit

Fix

Missing Authorization

Information Disclosure

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62328
GHSA-VJC7-JRH9-9J86

Affected Products

9Router