9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback destinations, allowing unauthenticated attackers when dashboard login is disabled to scan internal services and reflect OIDC discovery fields including token_endpoint and jwks_uri.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback destinations, allowing unauthenticated attackers when dashboard login is disabled to scan internal services and reflect OIDC discovery fields including token_endpoint and jwks_uri. | |
| Title | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | |
| Weaknesses | CWE-306 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T21:14:06.082Z
Reserved: 2026-06-22T16:39:01.044Z
Link: CVE-2026-56677
No data.
Status : Received
Published: 2026-08-17T22:17:14.970
Modified: 2026-08-17T22:17:14.970
Link: CVE-2026-56677
No data.
OpenCVE Enrichment
No data.