GHSA-vjc7-jrh9-9j86: 9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
Multiple critical API security vulnerabilities were discovered in 9Router’s Next.js dashboard. The /api/providers endpoints lack authentication entirely, allowing anyone to create, read, update, and delete provider connections. Additionally, /api/usage/stats exposes full plaintext API keys, and /api/usage/request-logs + /api/usage/request-details expose all users’ request history and full conversation contents (including system prompts, user messages, assistant responses) without authentication.
References
Code Behaviors & Features
Detect and mitigate GHSA-vjc7-jrh9-9j86 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →