{"data":{"id":"828a3b5a-268c-4aa9-8c2a-efe1d84e262e","title":"GHSA-8gmq-j984-vp4r: 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass","summary":"## Summary\n\n9router is a software that provides an LLM proxy (a middleman service that connects to AI providers like OpenAI). It's supposed to require an API key (a secret credential) for access, but there's a bypass vulnerability: requests sent to `/codex/*` are secretly rewritten to `/api/v1/responses` by the server configuration, and since the authorization check (middleware, a security layer that runs before the main code) only protects specific paths and doesn't include `/codex`, unauthenti","solution":"N/A — no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-8gmq-j984-vp4r","publishedAt":"2026-08-28T18:32:01.000Z","cveId":"CVE-2026-55638","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["9router@< 0.5.2 (fixed: 0.5.2)"],"affectedVendors":["OpenAI","Anthropic"],"affectedVendorsRaw":["9router","OpenAI","Anthropic"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00611,"patchAvailable":true,"disclosureDate":"2026-08-28T18:32:01.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}