CVE-2026-55641: 9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated at...

Added to the CISA Known Exploited Vulnerabilities catalog on 10 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.2.

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default configuration, this...

Required action: Review and patch if applicable to your AI infrastructure.