Retour aux alertes CVE
CVE-2026-56676 HIGH CVSS 7.4

CVE-2026-56676 — HIGH

Publiée 1 month ago Fiche NVD officielle

Qu'est-ce que c'est ?

9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side image fetch with a separate DNS resolution. An authenticated attacker with access to the LLM proxy can use a vision-capable model and an attacker-controlled DNS name that first resolves to a public IP and then rebinds to an internal address, allowing server-side requests to internal-only HTTP services. This issue is fixed in version 0.5.2.

Technologies affectées

Non précisé par la fiche NVD.

Recommandation

Vérifie la disponibilité d'un correctif pour la technologie concernée et applique-le dès que possible. Consulte la fiche NVD pour les références officielles du fournisseur.

Exploits publics connus (0)

Aucun proof-of-concept public trouvé sur GitHub à ce jour. Ça peut changer : les PoC sont souvent publiés plusieurs jours ou semaines après la divulgation.