{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/9router-app--0.5.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:9router:9router:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-56681"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["9router-app (\u003c= 0.5.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","auth-bypass"],"_cs_type":"advisory","_cs_vendors":["9router"],"content_html":"\u003cp\u003e9router versions 0.5.4 and earlier contain a critical authentication bypass vulnerability (CVE-2026-56681) within the public LLM API layer. The application improperly trusts the user-supplied 'X-9r-Real-Ip' HTTP header to determine if a request originates from the local host (localhost). Under default deployment modes where the intended 'custom-server.js' security wrapper is absent, the application fails to strip or sanitize this header from inbound client traffic. A remote, unauthenticated attacker can inject 'X-9r-Real-Ip: 127.0.0.1' into HTTP requests to 'isLocalRequest()', which then instructs 'canAccessPublicLlmApi()' to waive mandatory API key validation. This vulnerability permits unauthorized access to the LLM provider resources configured by the instance owner, potentially leading to significant financial loss and account abuse.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target 9router instance exposed via port 80/443 without the custom-server.js wrapper.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET request to a protected endpoint, such as '/api/v1/models'.\u003c/li\u003e\n\u003cli\u003eAttacker adds the header 'X-9r-Real-Ip: 127.0.0.1' to the HTTP request.\u003c/li\u003e\n\u003cli\u003eThe 9router application receives the request and executes 'isLocalRequest()' in 'src/dashboardGuard.js'.\u003c/li\u003e\n\u003cli\u003eThe application erroneously reads the spoofed header value and returns 'true' for local origin validation.\u003c/li\u003e\n\u003cli\u003eThe logic proceeds to 'canAccessPublicLlmApi()', which identifies the request as 'local' and skips API key authentication.\u003c/li\u003e\n\u003cli\u003eThe application returns '200 OK', granting the attacker access to the model catalog and provider proxy.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass API key enforcement on the public LLM API. Impact includes the unauthorized consumption of the instance owner's paid LLM API credits, unauthorized access to configured provider infrastructure, enumeration of private model configurations, and potential abuse of upstream LLM provider accounts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade 9router to a version that implements secure transport-level source validation, or ensure deployment uses the required 'custom-server.js' wrapper to sanitize headers.\u003c/li\u003e\n\u003cli\u003eImplement a web application firewall (WAF) rule to block or strip the 'X-9r-Real-Ip' header from any incoming public traffic.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to access the '/api/v1/' path with the malicious header present in web server logs.\u003c/li\u003e\n\u003cli\u003eAudit current environment configurations to ensure 'custom-server.js' is correctly protecting all public-facing instances.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T19:53:39Z","date_published":"2026-09-22T19:53:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-9router-auth-bypass/","summary":"9router is vulnerable to an authentication bypass via a spoofable X-9r-Real-Ip HTTP header, allowing unauthenticated attackers to access LLM API endpoints.","title":"Authentication Bypass in 9router Public LLM API","url":"https://feed.craftedsignal.io/briefs/2026-09-9router-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - 9router-App (\u003c= 0.5.4)","version":"https://jsonfeed.org/version/1.1"}