CVE-2026-46339

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-15 21:16

Updated : 2026-07-16 14:16


NVD link : CVE-2026-46339

Mitre link : CVE-2026-46339

CVE.ORG link : CVE-2026-46339


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-306

Missing Authentication for Critical Function