Vulnerability Description
9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/decolua/9router/commit/992f4db4a0d858bcc86b4786f2abab117a6ccd
- https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj
- https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj
FAQ
What is CVE-2026-46339?
CVE-2026-46339 is a vulnerability with a CVSS score of 10.0 (CRITICAL). 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugi...
How severe is CVE-2026-46339?
CVE-2026-46339 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-46339?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.