{"id":"CVE-2026-46339","aliases":["GHSA-fhh6-4qxv-rpqj"],"url":"https://o3.security/vulnerability/CVE-2026-46339","summary":"9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes","details":"9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.","published":"2026-07-15T20:41:06.937Z","modified":"2026-08-12T03:51:27.329124118Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.02395,"percentile":0.82525,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"9router","fixedVersion":"0.4.37"}],"fix":{"url":"https://github.com/decolua/9router/commit/992f4db4a0d858bcc86b4786f2abab117a6ccdf8","label":"decolua/9router@992f4db"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46339.json"},{"type":"ADVISORY","url":"https://github.com/decolua/9router/security/advisories/GHSA-fhh6-4qxv-rpqj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46339"},{"type":"FIX","url":"https://github.com/decolua/9router/commit/992f4db4a0d858bcc86b4786f2abab117a6ccdf8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.329124118Z"}}