Description
A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server-side request forgery via the Retrieval Completion API endpoint
Action: Patch Immediately
AI Analysis

Impact

A flaw in SciPhi-AI R2R allows an attacker to modify the `generation_config.api_base` argument in the Retrieval Completion API endpoint, resulting in the server making HTTP requests to arbitrary addresses. This server-side request forgery can direct the component to internal or external resources, potentially exposing sensitive data or enabling further exploitation. The vulnerability is strictly limited to SSRF and does not specify additional capabilities such as credential theft or lateral movement.

Affected Systems

SciPhi‑AI R2R versions up to and including 3.6.6 are affected. No newer releases were reported as vulnerable, so any deployment running 3.6.6 or earlier should be considered at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the exploit is publicly available. Although EPSS data is not provided and the vulnerability is not listed in the CISA KEV catalog, the remote attack vector via a crafted request to the Retrieval Completion API endpoint is directly feasible. The lack of a KEV listing does not reduce the potential risk; an attacker can leverage the vulnerable API to issue arbitrary requests to internal or external addresses.

Generated by OpenCVE AI on October 4, 2026 at 13:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SciPhi-AI R2R to a version newer than 3.6.6 or apply an official patch if available
  • If an update is not immediately possible, restrict outbound traffic from the R2R service with a firewall or proxy, allowing requests only to trusted endpoints to block abuse of the `api_base` parameter
  • Implement input validation or sanitization on the `generation_config.api_base` field, or disable the feature that accepts user-controlled URLs until a fix is deployed

Generated by OpenCVE AI on October 4, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title SciPhi-AI R2R Retrieval Completion API Endpoint llm.py server-side request forgery
First Time appeared Sciphi-ai
Sciphi-ai r2r
Weaknesses CWE-918
CPEs cpe:2.3:a:sciphi-ai:r2r:*:*:*:*:*:*:*:*
Vendors & Products Sciphi-ai
Sciphi-ai r2r
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T11:30:12.942Z

Reserved: 2026-10-03T18:05:17.570Z

Link: CVE-2026-105148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T13:16:55.733

Modified: 2026-10-04T13:16:55.877

Link: CVE-2026-105148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T14:00:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)