9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass — GHSA-8GMQ-J984-VP4R
GitHub · GitHub · GHSA-8GMQ-J984-VP4R
ID
GHSA-8GMQ-J984-VP4R
GHSA-8GMQ-J984-VP4R
Datum
Quelle
GitHub
GitHub
Vendor
GitHub
GitHub
Risiko
hoch
hoch
CVSS
8.6
8.6
EPSS
0.00611
0.00611
Zusammenfassung
## Summary 9router exposes an OpenAI/Anthropic-compatible LLM proxy. Remote access to this proxy is intended to be protected by an API-key check in the Next.js middleware. However, 9router also defines a rewrite that maps `/codex/*` to the backend LLM endpoint `/api/v1/responses`. The middleware authorization decision is made on the incoming request path before the rewrite is applied. Because `/codex` is not…
Zeitlicher Verlauf
- Von der Quelle veröffentlicht
- 2026-08-28
Risikokontext
- Gemeldeter Schweregrad oder Risikowert: hoch.
- Gemeldeter CVSS-Wert: 8.6 von 10.
- Gemeldeter EPSS-Wert: 0.00611.
- Prüfe die Exponierung für das betroffene Produkt oder die Produktfamilie: npm: 9router.
Produkt
npm: 9router
Was tun?
Allgemeine, vorsichtige Schritte (bitte prüfe die offizielle Quelle für Details):
- Priorisiere sofort Patches oder Mitigations (hohes akutes Risiko).
- Identifiziere betroffene Produktversionen und prüfe, ob du betroffen bist.
- Spiele Hersteller-Updates/Patches ein oder setze empfohlene Mitigations um.
- Lies das offizielle Advisory für betroffene Versionen und konkrete Schritte.
Offizielles Advisory
Nachweise und Herkunft
- Kanonische Advisory-ID
- GHSA-8GMQ-J984-VP4R
- Quelle
- GitHub
- Vendor
- GitHub
- Von der Quelle veröffentlicht
- 2026-08-28
- Letzte Quellenaktivität
- 2026-08-28
- Weitere Kennungen
- CVE-2026-55638
- Kuratiert von
- hlukh.ch
Verwandte Hinweise und Zusammenhänge
Diese Hinweise sind anhand gemeinsamer CVE-, Produkt-, Hersteller-, Quellen- oder Zeitsignale verknüpft.