Impact
The vulnerability allows remote attackers to access sensitive user data without authentication. By sending requests to the unprotected request-logs and request-details API endpoints, an adversary can enumerate paginated logs and retrieve full AI conversation histories, including system prompts, user messages, assistant responses, tool calls, and user email addresses. The weakness corresponds to CWE-359 (Information Exposure through Log File) and CWE-862 (Missing Authorization).
Affected Systems
The impacted product is 9Router from decolua, specifically versions up to and including 0.4.41. Attackers can exploit the issue on any instance running these affected releases unless further hardening is applied.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, with no authentication or authorization required to reach the affected API routes. In the absence of additional constraints, any network‑connected instance of an affected 9Router version is vulnerable.
OpenCVE Enrichment