CVE-2026-105148
Deferred Deferred - Pending Action

Server-Side Request Forgery in SciPhi-AI R2R

Vulnerability report for CVE-2026-105148, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sciphi-ai r2r to 3.6.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105148 is a Server-Side Request Forgery (SSRF) vulnerability in the SciPhi-AI R2R framework up to version 3.6.6. It allows unauthenticated attackers to manipulate the generation_config.api_base parameter in the Retrieval Completion API Endpoint, forcing the server to send HTTP requests to arbitrary URLs controlled by the attacker. This can lead to internal service exposure or data exfiltration.

Detection Guidance

To detect this SSRF vulnerability in SciPhi-AI R2R, monitor network traffic for outbound HTTP requests originating from the R2R process to unexpected or internal IP addresses. Check logs for POST requests to /v3/retrieval/completion or /v3/retrieval/agent endpoints with the generation_config.api_base parameter set to arbitrary URLs. Use tools like tcpdump or Wireshark to capture outbound connections from the R2R container or process.

Impact Analysis

This vulnerability can allow attackers to access internal services, exfiltrate sensitive data like API keys, or interact with cloud metadata endpoints. If the server uses model prefixes like custom/ or together_ai/, the attacker can forward the OPENAI_API_KEY as an Authorization header in outbound requests, potentially leaking secrets.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection principles and HIPAA's security requirements for safeguarding sensitive information. Non-compliance risks include fines, legal penalties, and reputational damage due to potential breaches of confidentiality.

Mitigation Strategies

Immediately disable unauthenticated access by setting require_authentication = true in the R2R configuration. Block or restrict outbound HTTP requests from the R2R process to non-allowlisted hosts. Avoid accepting api_base or provider API keys from client requests; source them from server configuration instead. Update to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105148. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart