THREAT OPS › Threat News › [GHSA] GHSA-8gmq-j984-vp4r (high) — 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
[GHSA] GHSA-8gmq-j984-vp4r (high) — 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
GHSA-8gmq-j984-vp4r Severity: high CVE: CVE-2026-55638
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
## Summary
9router exposes an OpenAI/Anthropic-compatible LLM proxy. Remote access to this proxy is intended to be protected by an API-key check in the Next.js middleware.
However, 9router also defines a rewrite that maps `/codex/*` to the backend LLM endpoin
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 23da7b1fe3bb8edd2bdbdb63fbbb15a476b02c56sha1
- CVE-2026-55638cve
- evil.attacker.comdomain
Original source: https://github.com/advisories/GHSA-8gmq-j984-vp4r