CVE-2026-63732
published 2026-07-23CVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass…
PriorityP272critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.74%
51.0th percentile
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote, unauthenticated attacker can log in with the default credential, spoof the Host header to reach local-only routes, and register a malicious MCP plugin (e.g. node -e ) to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| decolua | 9router | < 0.4.60 | 0.4.60 |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spo
ghsa_unreviewed·2026-07-24
CVE-2026-63732 [CRITICAL] CWE-78 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spo
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote, unauthenticated attacker can log in with the default credential, spoof the Host header to reach local-only routes, and register a malicious MCP plugin (e.g. node -e ) to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.
VulDB
decolua 9router up to 0.4.59 MCP Plugin Registration child_process.spawn default password
vuldb·2026-07-23·CVSS 9.9
CVE-2026-63732 [CRITICAL] decolua 9router up to 0.4.59 MCP Plugin Registration child_process.spawn default password
A vulnerability was found in decolua 9router up to 0.4.59. It has been declared as very critical. Affected by this vulnerability is the function child_process.spawn of the component MCP Plugin Registration. Executing a manipulation can lead to use of default password.
This vulnerability is tracked as CVE-2026-63732. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-23
Published