CVE-2026-56679: Decolua 9router

High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.

9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing an authenticated user to set security-critical fields such as requireLogin and disable authentication for the whole application, exposing protected routes such as /api/keys and /api/providers to unauthenticated access. This issue is reported as fixed in version 0.5.4.

Affected products

  • Decolua 9router: before 0.5.4 (fixed in 0.5.4)

Published 2026-07-15. Last modified 2026-07-16.