Impact
The flaw resides in the JWT Secret Handler of SciPhi-AI R2R and allows hard‑coded bcrypt and NaCl secret keys to be used by default. With knowledge of these constants an attacker can forge or decrypt JSON Web Tokens, thereby bypassing authentication and potentially accessing protected data. The vulnerability can be triggered remotely and the exploit has been publicly disclosed.
Affected Systems
SciPhi‑AI R2R installations up to version 3.6.6 are affected. No information is provided about patches, so any deployment running these versions remains vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS data are not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote network access, and the public disclosure suggests that exploitation is likely possible without additional setup.
OpenCVE Enrichment