CVE-2026-46339

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
Configurations

No configuration.

History

16 Jul 2026, 14:16

Type Values Removed Values Added
References () https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj - () https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj -

15 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 21:16

Updated : 2026-07-16 14:16


NVD link : CVE-2026-46339

Mitre link : CVE-2026-46339

CVE.ORG link : CVE-2026-46339


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-306

Missing Authentication for Critical Function