CVE-2026-8081

A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/m3ngx1ng/cve/blob/main/CLIProxyAPI-SSRF.md Third Party Advisory
https://vuldb.com/submit/807811 Third Party Advisory VDB Entry
https://vuldb.com/vuln/361836 Third Party Advisory VDB Entry
https://vuldb.com/vuln/361836/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:router-for-me:cliproxyapi:6.9.29:*:*:*:*:*:*:*

History

12 May 2026, 20:27

Type Values Removed Values Added
CPE cpe:2.3:a:router-for-me:cliproxyapi:6.9.29:*:*:*:*:*:*:*
First Time Router-for-me
Router-for-me cliproxyapi
References () https://github.com/m3ngx1ng/cve/blob/main/CLIProxyAPI-SSRF.md - () https://github.com/m3ngx1ng/cve/blob/main/CLIProxyAPI-SSRF.md - Third Party Advisory
References () https://vuldb.com/submit/807811 - () https://vuldb.com/submit/807811 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/361836 - () https://vuldb.com/vuln/361836 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/361836/cti - () https://vuldb.com/vuln/361836/cti - Permissions Required, VDB Entry

07 May 2026, 18:51

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 18:16

Updated : 2026-05-12 20:27


NVD link : CVE-2026-8081

Mitre link : CVE-2026-8081

CVE.ORG link : CVE-2026-8081


JSON object : View

Products Affected

router-for-me

  • cliproxyapi
CWE
CWE-918

Server-Side Request Forgery (SSRF)