Sceawere
Vulnerability Detail
CVE-2026-108593UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
9router Config Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- decolua
- Product
- 9router
- Attack Type
- Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api/cli-tools/hermes-settings endpoint that allows authenticated dashboard users to inject arbitrary keys into the Hermes Agent config.yaml file. Attackers can submit a baseUrl containing double quotes and newlines to add hooks_auto_accept and a hooks.post_llm_call shell command, which Hermes Agent executes without approval after an LLM call.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T19:16:57.607Z",
"pubdate": "2026-10-10T19:16:57.607Z",
"executiveSummary": "The 9router application, specifically versions 0.4.1 through 0.5.99, is susceptible to a critical configuration injection vulnerability residing within the POST /api/cli-tools/hermes-settings endpoint.\nThe vulnerability stems from improper sanitization of user-supplied input intended for the Hermes Agent configuration file (config.yaml).\nAn authenticated dashboard user can manipulate the baseUrl parameter by injecting malicious syntax, including double quotes and newline characters.\nThis allows for the arbitrary modification of the configuration, specifically enabling 'hooks_auto_accept' and injecting a 'hooks.post_llm_call' command.\nBecause the Hermes Agent executes these injected shell commands without requiring manual approval following an LLM call, the vulnerability facilitates Remote Code Execution (RCE) with the privileges of the agent process.\nThe risk is severe, as it allows attackers to gain unauthorized command execution on the host system. Successful exploitation requires valid authentication to the dashboard, though the impact is significant due to the lack of secondary validation for system-level hooks.",
"technicalDetails": "The vulnerability is located in the backend processing logic of the POST /api/cli-tools/hermes-settings endpoint within the 9router application. The root cause is the failure to perform rigorous validation or sanitization on the 'baseUrl' configuration parameter before appending it to the 'config.yaml' file utilized by the Hermes Agent.\nThe Hermes Agent relies on this configuration file to manage various operational hooks. Because the application blindly accepts input strings without escaping control characters or quote delimiters, an attacker can perform a configuration injection attack.\nThe attack flow proceeds as follows: First, the attacker authenticates to the 9router dashboard. Second, the attacker issues a specially crafted POST request to the '/api/cli-tools/hermes-settings' endpoint. Within the request body, the 'baseUrl' parameter is manipulated to include newline characters (e.g., %0A) followed by key-value pairs that inject configuration directives into 'config.yaml'.\nAn attacker can insert lines such as 'hooks_auto_accept: true' and 'hooks.post_llm_call: [malicious_command]'. By utilizing the newline character, the attacker successfully breaks out of the intended 'baseUrl' field context to write new lines into the YAML configuration format. The Hermes Agent periodically reloads or initializes its settings based on the 'config.yaml' file.\nOnce the agent processes the tainted configuration, it interprets the injected 'hooks.post_llm_call' directive as a legitimate shell command to be executed after every Large Language Model (LLM) interaction. Consequently, whenever an LLM call is triggered through the system, the Hermes Agent executes the injected shell command with the privileges of the service user, leading to full Remote Code Execution (RCE) on the underlying host.\nThis vulnerability is restricted to authenticated dashboard users, but the privilege level required is minimal as standard dashboard access is sufficient to trigger the endpoint. The lack of an approval workflow for these hooks is a design flaw that exacerbates the impact of the injection, as the agent blindly executes code defined in a user-writable configuration file without further verification or sandboxing."
}