Skip to content
Critical Vulnerabilities in SciPhi-AI/R2R Expose Users to SSRF and JWT Attacks

Critical Vulnerabilities in SciPhi-AI/R2R Expose Users to SSRF and JWT Attacks

First seen 4 Oct 2026, 18:01 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 19:00 UTC
  • •Two critical vulnerabilities in SciPhi-AI/R2R affect version 3.6.6.
  • •The SSRF vulnerability allows unauthorized HTTP requests via a client-controlled API base.
  • •The JWT vulnerability enables token minting using hard-coded secrets, compromising user accounts.

Two critical vulnerabilities have been identified in the SciPhi-AI/R2R product, affecting version 3.6.6. The first vulnerability (CWE-918) allows server-side request forgery (SSRF) due to a client-controlled API base, leading to unauthorized HTTP requests. The second vulnerability (CWE-321) involves hard-coded cryptographic keys, allowing attackers to mint valid access tokens without authentication. Both vulnerabilities were tested against a default Docker deployment on 2026-08-25, with CVSS scores of 9.2 and 9.8 respectively, indicating a high severity. The vulnerabilities have not yet been patched, and users are advised to monitor for updates. Security advisories recommend filing these issues privately until a fix is released.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-25
Vulnerabilities tested
Both SSRF and JWT vulnerabilities were tested against a default Docker deployment, confirming their exploitability.
Article 1
2026-10-04
Vulnerabilities disclosed
The vulnerabilities were publicly disclosed on the same day, highlighting their critical nature and impact.
Article 2

More articles in this cluster (2)

Common questions

What versions of SciPhi-AI/R2R are affected?
The vulnerabilities affect version 3.6.6 of SciPhi-AI/R2R.
What are the main risks associated with these vulnerabilities?
The SSRF vulnerability can lead to unauthorized access to internal services, while the JWT vulnerability allows attackers to impersonate users.
Is there a patch available for these vulnerabilities?
No, there is currently no patch available; users should monitor for updates from the vendor.