GHSA-ggrj-5337-qvwmMediumCVSS 7.3
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-103530
- https://github.com/decolua/9router/issues/3714
- https://github.com/decolua/9router/pull/3723
- https://github.com/decolua/9router
- https://vuldb.com/cve/CVE-2026-103530
- https://vuldb.com/submit/956865
- https://vuldb.com/vuln/412342
- https://vuldb.com/vuln/412342/cti
- https://github.com/advisories/GHSA-ggrj-5337-qvwm