Vulnerabilidades em decolua
20 resultadosAnálise Vexday
A Decolua apresenta 18 vulnerabilidades registradas, com concentração preocupante de 17 publicações nos últimos 90 dias, indicando risco emergente. Embora nenhuma esteja sob exploração ativa conhecida (KEV), 6 vulnerabilidades críticas e a fraqueza dominante em autenticação insuficiente (CWE-306) demandam atenção imediata para mitigação.
CVE-2026-46339CRITICAL9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routesEPSS 2.4%CVE-2026-59801CRITICAL9Router 0.4.41 - Unauthenticated API Exposure via /api/providersEPSS 2.2%CVE-2026-59800CRITICAL9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install EndpointEPSS 1.3%CVE-2026-63732CRITICAL9router before 0.4.60 Remote Code Execution via default passwordEPSS 0.7%CVE-2026-62312HIGH9Router: Authenticated RCE via Unvalidated MCP Plugin ArgumentsEPSS 0.7%CVE-2026-49352CRITICAL9Router: Hardcoded Default fallback JWT Secret Allows Authentication BypassEPSS 0.4%CVE-2026-55500CRITICAL9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database TakeoverEPSS 0.4%CVE-2026-55638HIGH9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypassEPSS 0.4%CVE-2026-62328HIGH9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage EndpointsEPSS 0.4%CVE-2026-62327CRITICAL9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/statsEPSS 0.4%CVE-2026-63313HIGH9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetchEPSS 0.3%CVE-2026-56679HIGH9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgradeEPSS 0.3%CVE-2026-55501HIGH9router: Login brute-force protection bypass via spoofed X-Forwarded-For headerEPSS 0.3%CVE-2026-56675HIGH9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIsEPSS 0.3%CVE-2026-5842MEDIUMdecolua 9router Administrative API Endpoint api authorizationEPSS 0.3%CVE-2026-10269MEDIUMdecolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorizationEPSS 0.3%CVE-2026-55641HIGH9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRFEPSS 0.2%CVE-2026-49353HIGH9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofINGEPSS 0.2%CVE-2026-56678MEDIUM9Router: Kiro region injection allows authenticated SSRF with Authorization header forwardingEPSS 0.2%CVE-2026-56676HIGH9router: Image prefetch DNS rebinding allows SSRF to internal servicesEPSS 0.2%