{"data":{"id":"289292a9-da9d-44a6-b587-128ec275b62b","title":"GHSA-86m2-fcxq-5q7c: 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF","summary":"9router has a critical authentication bypass where attackers can spoof the `Host` header (a message field that tells the server which domain is being accessed) to trick the application into treating their requests as local, granting them unauthenticated access to the `/v1` AI proxy endpoint. This allows attackers to make requests to AI services using the victim's paid API keys, stealing costs and data, or to perform SSRF (server-side request forgery, where the attacker makes the server fetch URLs of their choosing) attacks against internal systems.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-86m2-fcxq-5q7c","publishedAt":"2026-08-28T18:33:20.000Z","cveId":"CVE-2026-55641","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["prompt_injection","supply_chain"],"issueType":"vulnerability","affectedPackages":["9router@< 0.5.2 (fixed: 0.5.2)"],"affectedVendors":[],"affectedVendorsRaw":["9router"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00323,"patchAvailable":true,"disclosureDate":"2026-08-28T18:33:20.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010","AML.T0051"]}}