What is CVE-2026-63313?
9Router versions before 0.4.72 contain a server-side request forgery (SSRF) vulnerability in the `/v1/web/fetch` endpoint. A user-controlled URL parameter is passed to external scraping providers, which could allow attackers to make unauthorized requests. Immediate update to the latest version is recommended.
Azərbaycanca: 9Router-in 0.4.72-dən əvvəlki versiyalarında `/v1/web/fetch` endpoint-də server-side request forgery (SSRF) zəifliyi aşkarlanıb. İstifadəçi tərəfindən idarə olunan URL parametri xarici scraping servislərinə ötürülür. Təsirə məruz qalmamaq üçün dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of 9Router are affected by CVE-2026-63313?
This SSRF vulnerability affects 9Router versions before 0.4.72.
What action should be taken to mitigate CVE-2026-63313?
Immediate update to the latest version of 9Router is recommended to avoid exposure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.