CVE-2026-103530: Decolua 9router
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.
Affected products
- Decolua 9router: version 0.5.0 only; version 0.5.1 only; version 0.5.2 only; version 0.5.3 only; version 0.5.4 only; version 0.5.5 only; …
Published 2026-10-01. Last modified 2026-10-01.