PT-2026-96820 · 9Router+1 · 9Router+1
CVE-2026-56681
·
Published
2026-09-22
·
Updated
2026-09-28
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
9Router versions prior to 0.5.6
Description
Deployments that allow requests to reach Next.js without the sanitizing
custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header. In src/dashboardGuard.js, the isLocalRequest() function uses this header to determine if a request originates from localhost. If the header is set to 127.0.0.1, the canAccessPublicLlmApi() function may skip API-key validation for routes under the /api/v1/* endpoint, such as the GET /api/v1/models route. A remote unauthenticated attacker can exploit this by spoofing the X-9r-Real-Ip header to be classified as a local client, allowing unauthorized use of the instance owner's configured LLM providers, consumption of paid credits, and enumeration of configured providers and models.Recommendations
Update to version 0.5.6.
As a temporary mitigation, ensure the
custom-server.js wrapper is used to sanitize requests or restrict access to the /api/v1/* endpoint to prevent remote attackers from supplying the X-9r-Real-Ip header.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
9Router
Next.Js