Skip to content

Known CVE

9Router - Unauthenticated LLM Provider API Exposure

9Router through version 0.4.41 contains an unauthenticated access vulnerability caused by missing authentication middleware in Next.js API routes under src/app/api/providers/*, letting remote attackers enumerate, create, modify, or delete provider connections, exploit requires no authentication.

CVE-2026-59801

Critical2026

9router · unauth · api-exposure · misconfig · api-key-leak

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website