PT-2026-96820 · 9Router+1 · 9Router+1

CVE-2026-56681

·

Published

2026-09-22

·

Updated

2026-09-28

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions 9Router versions prior to 0.5.6
Description Deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header. In src/dashboardGuard.js, the isLocalRequest() function uses this header to determine if a request originates from localhost. If the header is set to 127.0.0.1, the canAccessPublicLlmApi() function may skip API-key validation for routes under the /api/v1/* endpoint, such as the GET /api/v1/models route. A remote unauthenticated attacker can exploit this by spoofing the X-9r-Real-Ip header to be classified as a local client, allowing unauthorized use of the instance owner's configured LLM providers, consumption of paid credits, and enumeration of configured providers and models.
Recommendations Update to version 0.5.6. As a temporary mitigation, ensure the custom-server.js wrapper is used to sanitize requests or restrict access to the /api/v1/* endpoint to prevent remote attackers from supplying the X-9r-Real-Ip header.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56681
GHSA-5MJ8-GF6M-FHW8

Affected Products

9Router
Next.Js