CVE-2026-46339
CRITICAL NUCLEI9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
Title source: cnaExploitation Summary
CVE-2026-46339 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
Nuclei Templates (1)
9Router <= 0.4.36 - Unauthenticated RCE
CRITICALVERIFIEDby 0x_Akoko
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj
X_Refsource_Misc x_refsource_misc
https://github.com/decolua/9router/commit/992f4db4a0d858bcc86b4786f2abab117a6ccdf8
Scores
CVSS v3
10.0
EPSS
0.0239
EPSS Percentile
82.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
CWE-78
Status
published
Products (1)
decolua/9router
>= 0.4.30, < 0.4.37
Published
Jul 15, 2026
Tracked Since
Jul 16, 2026