CVE-2026-56681

CVE-2026-56681 published: 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when isLocalRequest decide...

View full NVD advisory → ← Back to CVE watch