CVE-2026-56676: 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side i...
Added to the CISA Known Exploited Vulnerabilities catalog on 10 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.4.
9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side image fetch with a separate DNS resolution. An authenticated attacker with access to the LLM proxy ca...
Required action: Review and patch if applicable to your AI infrastructure.