PT-2026-57907 · 9Router · 9Router
CVE-2026-62328
·
Published
2026-07-06
·
Updated
2026-07-13
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
9Router versions prior to 0.4.42
Description
An unauthenticated information disclosure issue allows remote attackers to access sensitive user data. By querying the 'request-logs' and 'request-details' API endpoints, which lack authentication middleware, attackers can enumerate paginated request logs and retrieve complete AI conversation histories. This exposed data includes system prompts, user messages, assistant responses, tool calls, and user email addresses.
Recommendations
Update 9Router to version 0.4.42 or later.
Restrict access to the 'request-logs' and 'request-details' API endpoints until the update is applied.
Exploit
Fix
Missing Authorization
Information Disclosure
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
9Router