CVE-2026-49352Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an auth_token cookie when JWT_SECRET was unset. This issue is fixed in version 0.4.44

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-11: 1Technical Details · 2026-08-11: 108-11
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    Every week brings new attack surface. CVE-2026-49352 — take a look. 9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass The best defense is the one you set up before you needed it.

    Post summary

    The post announces CVE-2026-49352, detailing an authentication bypass due to 9router’s hardcoded default JWT secret, but offers no proof‑of‑concept, exploit details, active exploitation evidence, or patch information.

    0000051
    355 followersView on X

Explore more