{"apiVersion":"1.0","identifier":"CVE-2026-56677","description":"9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback destinations, allowing unauthenticated attackers when dashboard login is disabled to scan internal services and reflect OIDC discovery fields including token_endpoint and jwks_uri.","publishedAt":"2026-08-17T22:17:14","lastModifiedAt":"2026-08-18T16:17:59","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56677","cvssScore":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","epssProbability":0.00271,"riskScore":0.88,"affectedProduct":"9Router","affectedVersions":"<=0.5.4","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-56677","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-56677","en":"https://www.redsauce.net/en/cves/CVE-2026-56677","fr":"https://www.redsauce.net/fr/cves/CVE-2026-56677","pt":"https://www.redsauce.net/pt/cves/CVE-2026-56677","de":"https://www.redsauce.net/de/cves/CVE-2026-56677","sk":"https://www.redsauce.net/sk/cves/CVE-2026-56677","el":"https://www.redsauce.net/el/cves/CVE-2026-56677"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-56677"}}