CVE-2026-49353: Decolua 9router

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to protect /api/mcp/*, /api/tunnel/*, and /api/cli-tools/*, allowing header spoofing in reverse proxy or tunnel deployments to reach MCP child process stdin paths.

Affected products

  • Decolua 9router: up to and including 0.4.45

Published 2026-07-15. Last modified 2026-07-16.