CVE-2026-8081

A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/m3ngx1ng/cve/blob/main/CLIProxyAPI-SSRF.md Third Party Advisory
https://vuldb.com/submit/807811 Third Party Advisory VDB Entry
https://vuldb.com/vuln/361836 Third Party Advisory VDB Entry
https://vuldb.com/vuln/361836/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:router-for-me:cliproxyapi:6.9.29:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-07 18:16

Updated : 2026-06-17 11:03


NVD link : CVE-2026-8081

Mitre link : CVE-2026-8081

CVE.ORG link : CVE-2026-8081


JSON object : View

Products Affected

router-for-me

  • cliproxyapi
CWE
CWE-918

Server-Side Request Forgery (SSRF)