<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:06:28.374001+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338216</id>
    <title>EUVD-2026-338216</title>
    <updated>2026-10-06T16:06:28.420859+00:00</updated>
    <content>EUVD-2026-338216</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338216"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56679</id>
    <title>fkie_cve-2026-56679</title>
    <updated>2026-10-06T16:06:28.420897+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>9Router is an AI router &amp; token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing an authenticated user to set security-critical fields such as requireLogin and disable authentication for the whole application, exposing protected routes such as /api/keys and /api/providers to unauthenticated access. This issue is reported as fixed in version 0.5.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vmjq-hvgq-2wv4</id>
    <title>GHSA-vmjq-hvgq-2wv4 — 9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade</title>
    <updated>2026-10-06T16:06:28.420931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: 9router</p>
<p>### Summary
The `PATCH /api/settings` endpoint writes the entire request body to persistent settings without a field whitelist. An authenticated user can set security-critical fields that are not meant to be modifiable here — notably `requireLogin`. Setting `requireLogin: false` disables authentication for the whole application, exposing all protected routes (e.g. `/api/keys`, `/api/providers`) to unauthenticated access.</p>
<p>### Details
Root cause is unfiltered mass assignment (CWE-915):</p>
<p>- `src/app/api/settings/route.js` (PATCH handler) parses the body and passes it to `updateSettings(body)`, with special handling only for `newPassword` and `oidcClientSecret`. All other fields pass through.
- `src/lib/db/repos/settingsRepo.js` — `updateSettings` does `next = { ...current, ...updates }`, so any key in the body overwrites stored settings, including `requireLogin`, `tunnelDashboardAccess`, `authMode`.
- `src/dashboardGuard.js` — `isAuthenticated` returns `true` whenever `settings.requireLogin === false`, bypassing auth on all protected routes.</p>
<p>This is distinct from CVE-2026-5842 (CWE-285, pre-auth bypass on `/api`, patched in 0.3.75). This finding requires a valid authenticated session and abuses input handling, not missing authentication.</p>
<p>### PoC
Instance on `localhost:20128`, default password `123456`.</p>
<p>1. Authenticate, capture session:
   `POST /api/auth/login` body `{"password":"123456"}` → `200 {"success":true}`
2. Mass-assign with the authenticated session:
   `PATCH /api…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vmjq-hvgq-2wv4"/>
  </entry>
</feed>
