Critical
github
·
GHSA-vjc7-jrh9-9j86
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
Published Jul 6, 2026
CVSS 10.0
title: Unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats product: 9Router version:
Affected AI Products
github copilot
copilot
openai