Skip to content
archivevulnerability · 22 Sep 2026 · 16:34 UTC

GHSA-5mj8-gf6m-fhw8: 9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header

VULNCVE-2026-56681source · GTH
HIGHHigh-risk vulnerability — CVSS 7.3

last 60 dispatches · spectrum

## Summary 9router determines whether an incoming request originates from localhost by trusting the X-9r-Real-Ip HTTP request header. This header is intended to be produced and sanitized exclusively by the bundled custom-server.js layer from the TCP socket address. In deployment modes where requests reach Next.js directly (the header is never stripped/regenerated), a remote, unauthenticated attacker can simply send X-9r-Real-Ip: 127.0.0.1 and be treated as a local client. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected