gist.github.com Critical Vulnerabilities in SciPhi-AI/R2R Expose Users to SSRF and JWT Attacks
Article Content
- •Two critical vulnerabilities in SciPhi-AI/R2R affect version 3.6.6.
- •The SSRF vulnerability allows unauthorized HTTP requests via a client-controlled API base.
- •The JWT vulnerability enables token minting using hard-coded secrets, compromising user accounts.
Two critical vulnerabilities have been identified in the SciPhi-AI/R2R product, affecting version 3.6.6. The first vulnerability (CWE-918) allows server-side request forgery (SSRF) due to a client-controlled API base, leading to unauthorized HTTP requests. The second vulnerability (CWE-321) involves hard-coded cryptographic keys, allowing attackers to mint valid access tokens without authentication. Both vulnerabilities were tested against a default Docker deployment on 2026-08-25, with CVSS scores of 9.2 and 9.8 respectively, indicating a high severity. The vulnerabilities have not yet been patched, and users are advised to monitor for updates. Security advisories recommend filing these issues privately until a fix is released.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What versions of SciPhi-AI/R2R are affected?
What are the main risks associated with these vulnerabilities?
Is there a patch available for these vulnerabilities?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…