SciPhi-AI R2R

5 known vulnerabilities in SciPhi-AI R2R, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105148 CVSS 5.5 medium A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file…
  • CVE-2026-105147 CVSS 5.5 medium A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This…
  • CVE-2026-82527 CVSS 8.7 high R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks…
  • CVE-2026-82526 CVSS 9.3 critical R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements…
  • CVE-2026-82271 CVSS 7.1 high R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to…