Sceawere

Vulnerability Detail

CVE-2026-105147UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hard-coded Secrets in R2R

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
SciPhi-AI
Product
R2R
Attack Type
Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-04T13:16:54.773Z",
  "pubdate": "2026-10-04T13:16:54.773Z",
  "executiveSummary": "SciPhi-AI R2R versions up to 3.6.6 contain a critical vulnerability involving the presence of hard-coded credentials within the JWT Secret Handler component.\nThe vulnerability stems from the use of static, pre-defined values for DEFAULT_BCRYPT_SECRET_KEY and DEFAULT_NACL_SECRET_KEY, which are utilized for cryptographic operations and authentication token signing.\nThis design flaw allows remote, unauthenticated attackers to potentially bypass security controls, forge authentication tokens, or decrypt sensitive data encrypted with these keys.\nGiven that the secrets are hard-coded in the source code or configuration, the risk of exploitation is severe, as these keys are consistent across all deployments using the affected versions.\nThe vulnerability is publicly disclosed, increasing the likelihood of exploitation by malicious actors targeting systems that have not implemented custom, secure key management.\nNo vendor response or patch has been documented, necessitating immediate manual remediation to prevent unauthorized access to the R2R infrastructure.",
  "technicalDetails": "The vulnerability is rooted in the improper implementation of secret management within the SciPhi-AI R2R JWT Secret Handler. Specifically, the application relies on hard-coded cryptographic constants—DEFAULT_BCRYPT_SECRET_KEY and DEFAULT_NACL_SECRET_KEY—to initialize security operations.\nIn a secure implementation, these keys should be injected at runtime via environment variables or a secure key management system (e.g., HashiCorp Vault, AWS KMS). By hard-coding these values, the developers have created a static security context where the cryptographic integrity of the entire system is compromised upon discovery of these keys.\nThe attack flow begins with the attacker identifying the target R2R instance. Because the secret keys are static and embedded within the application codebase of versions up to 3.6.6, an attacker can extract these values through static analysis of the source code or by accessing a publicly exposed instance of the package.\nOnce the secret keys are obtained, the attacker can leverage them to perform unauthorized operations. For the DEFAULT_BCRYPT_SECRET_KEY, if this key is used for password hashing or sensitive data derivation, an attacker could potentially perform offline brute-force attacks or manipulate hashes. For the DEFAULT_NACL_SECRET_KEY, an attacker can manipulate or forge Sodium-based cryptographic operations, including the signing of JWTs (JSON Web Tokens).\nBy forging a JWT, an attacker can bypass authentication mechanisms entirely. The attacker generates a token payload with arbitrary claims (such as administrative privileges), signs the token using the compromised DEFAULT_NACL_SECRET_KEY, and presents this forged token to the R2R API. The backend, validating the signature against the hard-coded key, will accept the malicious token as authentic, granting the attacker unauthorized access to protected functionalities.\nThe vulnerability is remotely exploitable, as it does not require prior local access to the server, only the ability to interact with the service endpoint that processes JWTs or encrypted traffic. This exposure allows for full privilege escalation and unauthorized access to application data, representing a complete breakdown of the authentication and authorization model within the R2R framework.\nPost-exploitation impact includes persistent unauthorized access, potential data exfiltration, and the ability to impersonate any user, including administrative accounts, thereby compromising the entire integrity of the R2R-managed environment."
}
CVE-2026-105147: Hard-coded Secrets in R2R (HIGH Severity, CVSS: 7.3) | Sceawere