Description
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server‑side Request Forgery (SSRF) exposing internal networks
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates from the fetch function in ssrfGuard.js, where manipulation of the provider_options.baseUrl argument lets a remote attacker cause the 9Router backend to issue arbitrary HTTP requests. This can lead to data exfiltration, internal network probing, or further compromise of backend services, representing a classic Server‑Side Request Forgery identified as CWE‑918.

Affected Systems

All installations of decolua 9Router up to and including version 0.5.55 are affected. Versions newer than 0.5.55 are not known to be vulnerable.

Risk and Exploitability

The CVSS base score of 6.9 indicates a moderate risk; the exploit is remotely triggered without authentication. The lack of an EPSS score or KEV listing suggests limited evidence of active exploitation, yet the attack path does not require privileged credentials and can potentially reach any reachable host from the server. The overall risk is moderate to high for environments with valuable internal resources.

Generated by OpenCVE AI on October 1, 2026 at 01:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a version newer than 0.5.55 where the SSRF bug is resolved.
  • If an upgrade is not immediately possible, modify the Search Endpoint to validate provider_options.baseUrl against a whitelist of trusted domains or reject any request containing absolute URLs that target internal networks.
  • Configure outbound firewall rules or service isolation so that the 9Router process cannot reach internal resources, limiting the potential impact of an SSRF exploitation.

Generated by OpenCVE AI on October 1, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.
Title decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery
First Time appeared Decolua
Decolua 9router
Weaknesses CWE-918
CPEs cpe:2.3:h:decolua:9router:*:*:*:*:*:*:*:*
Vendors & Products Decolua
Decolua 9router
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-01T14:23:03.729Z

Reserved: 2026-09-30T19:06:45.120Z

Link: CVE-2026-103530

cve-icon Vulnrichment

Updated: 2026-10-01T14:23:00.420Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T00:16:43.287

Modified: 2026-10-01T15:17:27.783

Link: CVE-2026-103530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T06:30:01Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)