PT-2026-38545 · Router For Me · Cliproxyapi

M3X1

·

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-8081

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-8081

Affected Products

Cliproxyapi