CVE-2026-103530 | decolua 9Router up to 0.5.55 Search Endpoint ssrfGuard.js fetch provider_options.baseUrl server-side request forgery (Issue 3714)

SecurityVulns

A vulnerability classified as critical has been found in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery.

This vulnerability is identified as CVE-2026-103530. The attack can be initiated remotely. There is not any exploit available.

Applying a patch is the recommended action to fix this issue.VulDB Recent EntriesRead More