decolua
12 exploits
Active since Jun 2026
9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CVSS 7.5
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVSS 10.0
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVSS 9.8
9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
CVSS 6.4
9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments
CVSS 8.8
9router < 0.4.80 - Database Export Credential Disclosure and Import Overwrite
CVSS 9.9
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CVSS 7.3
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVSS 8.6
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
CVSS 8.2
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
CVSS 8.3
9router: Image prefetch DNS rebinding allows SSRF to internal services
CVSS 7.4
decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization
CVSS 6.3