CVE-2026-46339
9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/ and /api/mcp/, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46339.json, https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj, https://nvd.nist.gov/vuln/detail/CVE-2026-46339, https://github.com/decolua/9router/commit/992f4db4a0d858bcc86b4786f2abab117a6ccdf8