CVE-2026-105147: fallo de gravedad media en SciPhi-AI R2R
SciPhi-AI R2R JWT Secret hard-coded credentials
Publicada el · Actualizada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 6.9epss 0.3%
probabilidad de explotación
0.3%top 81% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
SciPhi-AI · R2RPoCs públicas encontradas — 1
cve_referencegist.github.com/DReazer/6bc4f88053ec35f8358395bcc0d1a0bbno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — SciPhi-AI R2R
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-82526CRITICALR2R 3.6.6 SQL Injection via Vector Index Creation EndpointEPSS 0.7%CVE-2026-82527HIGHR2R 3.6.6 SQL Injection via Retrieval Search Filter KeyEPSS 0.5%CVE-2026-105148MEDIUMSciPhi-AI R2R Retrieval Completion API Endpoint llm.py server-side request forgeryEPSS 0.3%CVE-2026-82271HIGHR2R Missing Ownership Check Allows Modifying Other Users' ConversationsEPSS 0.3%