CVE-2026-56679: 9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing an authenticated user to set security-critical fields such as requireLogin and disable authentication for the whole application, exposing protected routes such as /api/keys and /api/providers to unauthenticated access. This issue is reported as fixed in version 0.5.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
9Routerto a version that resolves this vulnerability.Fixed in 0.5.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56679?
CVE-2026-56679 has a high severity rating of 8.7.
How do I fix CVE-2026-56679?
To fix CVE-2026-56679, update to version 0.5.4 or later of 9Router.
What does CVE-2026-56679 exploit?
CVE-2026-56679 exploits a mass assignment vulnerability in the PATCH /api/settings endpoint.
What impact does CVE-2026-56679 have?
CVE-2026-56679 allows authenticated users to downgrade authorization and alter critical security settings.
Is CVE-2026-56679 present in all versions of 9Router?
Yes, CVE-2026-56679 affects all versions of 9Router prior to version 0.5.4.