Multiple security vulnerabilities affecting 9router versions <= 0.5.2 have been identified in 9router, a high-risk vulnerability allowing authenticated authorization downgrade via mass assignment in the endpoint.
CVE-2026-56679 (CVSS 8.7 — Severity): An authenticated user can set security-critical fields that are not meant to be modifiable here — notably requireLogin. Setting requireLogin: false disables authentication for the whole application, exposing all protected routes to unauthenticated access.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting 9router versions <= 0.5.2 have been identified in 9router, a high-risk vulnerability allowing authenticated authorization downgrade via mass assignment in the endpoint.
CVE-2026-56679 (CVSS 8.7 — Severity): An authenticated user can set security-critical fields that are not meant to be modifiable here — notably requireLogin. Setting requireLogin: false disables authentication for the whole application, exposing all protected routes to unauthenticated access.[emaillocker id="1283"]
CVE-2026-5842 (CWE-285, pre-auth bypass on `/api`, patched in 0.3.75). This finding requires a valid authenticated session and abuses input handling, not missing authentication.
We recommend you to update 9router to version 0.5.4.
The following reports contain further technical details:
[/emaillocker]