THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8gmq-j984-vp4r (high) — 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

[GHSA] GHSA-8gmq-j984-vp4r (high) — 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

highgithub_advisoriesPublished 2026-08-28

GHSA-8gmq-j984-vp4r Severity: high CVE: CVE-2026-55638

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

## Summary

9router exposes an OpenAI/Anthropic-compatible LLM proxy. Remote access to this proxy is intended to be protected by an API-key check in the Next.js middleware.

However, 9router also defines a rewrite that maps `/codex/*` to the backend LLM endpoin

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8gmq-j984-vp4r