Known CVE
9Router - Unauthenticated LLM Provider API Exposure
9Router through version 0.4.41 contains an unauthenticated access vulnerability caused by missing authentication middleware in Next.js API routes under src/app/api/providers/*, letting remote attackers enumerate, create, modify, or delete provider connections, exploit requires no authentication.
CVE-2026-59801
Critical2026
9router · unauth · api-exposure · misconfig · api-key-leak
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website