CVE-2026-46339 is an unauthenticated remote code execution vulnerability in decolua 9Router affecting versions 0.4.30 through 0.4.36. The flaw is caused by src/proxy.js failing to enforce protection on the /api/cli-tools/* and /api/mcp/* route families. As a result, an unauthenticated attacker can access functionality that should have been restricted, including registration of customPlugins through the cowork-settings route and command execution through the MCP bridge. The issue is fundamentally an authentication failure on sensitive endpoints that exposes command-execution-capable functionality to remote unauthenticated users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one executable Python proof-of-concept script, an MIT license, and a README. The script accepts a target URL and command, defaulting to `http://localhost:20128` and `id > /tmp/ctt_rce_proof.txt`. It POSTs a JSON `customPlugins` array to `/api/cli-tools/cowork-settings`; 32 entries are inert echo commands and the 33rd is a shell command that invokes Node.js `child_process.execSync` with the supplied command. It then GETs `/api/mcp/ctt-vector-32/sse` to trigger the final plugin. The claimed temporal/Riemann/wedge techniques are cosmetic: they generate labels and custom headers but do not materially transform, fragment, or conceal the executable command, which remains contained in the final plugin definition. The exploit is therefore an operational HTTP-based RCE attempt contingent on the claimed unauthenticated plugin-registration and MCP-trigger behavior existing on the target.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated command execution vulnerability in decolua 9Router caused by missing protection on /api/cli-tools/* and /api/mcp/* endpoints, enabling unauthenticated custom plugin registration and command execution via the MCP bridge.
A vulnerability identified as CVE-2026-46339, described in the content as involving unauthenticated remote code execution (RCE).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.