漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
Vulnerability Description
9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default configuration, this exposes the /v1 proxy to upstream provider calls using stored provider credentials and allows /v1/search with the searxng provider_options.baseUrl parameter to drive server-side requests to internal or cloud-metadata hosts. This issue is fixed in version 0.5.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
decolua 9router 配置错误漏洞
Vulnerability Description
decolua 9Router是decolua基金会的一个智能路由与降级的AI模型代理工具。 decolua 9Router 0.5.2之前版本存在安全漏洞,该漏洞源于读取客户端控制的Host标头,允许远程未经验证攻击者通过发送Host: localhost绕过API密钥身份验证,并利用searxng provider_options.baseUrl参数向内部或云元数据主机发出服务端请求。
CVSS Information
N/A
Vulnerability Type
N/A