Impact
A flaw in SciPhi-AI R2R allows an attacker to modify the `generation_config.api_base` argument in the Retrieval Completion API endpoint, resulting in the server making HTTP requests to arbitrary addresses. This server-side request forgery can direct the component to internal or external resources, potentially exposing sensitive data or enabling further exploitation. The vulnerability is strictly limited to SSRF and does not specify additional capabilities such as credential theft or lateral movement.
Affected Systems
SciPhi‑AI R2R versions up to and including 3.6.6 are affected. No newer releases were reported as vulnerable, so any deployment running 3.6.6 or earlier should be considered at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the exploit is publicly available. Although EPSS data is not provided and the vulnerability is not listed in the CISA KEV catalog, the remote attack vector via a crafted request to the Retrieval Completion API endpoint is directly feasible. The lack of a KEV listing does not reduce the potential risk; an attacker can leverage the vulnerable API to issue arbitrary requests to internal or external addresses.
OpenCVE Enrichment