Sceawere
Vulnerability Detail
CVE-2026-105148UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
R2R SSRF via API Base
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- SciPhi-AI
- Product
- R2R
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-04T13:16:55.733Z",
"pubdate": "2026-10-04T13:16:55.733Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in the SciPhi-AI R2R framework, specifically within the Retrieval Completion API Endpoint. This vulnerability, affecting versions up to 3.6.6, stems from improper validation of user-supplied input provided via the generation_config.api_base argument.\nBy manipulating the API base parameter, a remote, unauthenticated attacker can force the application to initiate unauthorized HTTP requests to arbitrary internal or external destinations. This facilitates the circumvention of network perimeters, potentially leading to unauthorized access to internal services, metadata endpoints (such as cloud instance metadata services), or local file system interaction via SSRF-capable protocols.\nThe risk is considered significant due to the availability of public exploits and the lack of vendor response, leaving the current user base exposed to exploitation. Security posture should be evaluated based on the ability of the R2R server to initiate outbound connections from its host environment.",
"technicalDetails": "The vulnerability resides within the py/shared/abstractions/llm.py file, which handles the orchestration of LLM-based completion requests. The Retrieval Completion API Endpoint fails to properly sanitize or validate the generation_config.api_base parameter before incorporating it into the underlying networking library responsible for communicating with the specified LLM service provider.\nThe root cause is an insecure configuration handling mechanism where the application trusts the user-provided base URL string to define the destination for LLM API calls. Since the application blindly forwards this parameter to its request handler, an attacker can supply an arbitrary URL, including local addresses (e.g., http://127.0.0.1) or internal network segments that are otherwise inaccessible from the public internet.\nThe attack flow proceeds as follows: First, the attacker identifies the Retrieval Completion API endpoint as the vector. Second, the attacker crafts a malicious request payload where the generation_config object includes a modified api_base argument targeting a sensitive internal resource. Third, the application receives this input and uses it to construct an outbound request via py/shared/abstractions/llm.py. Fourth, the server executes the HTTP call to the attacker-defined URL, returning the response—or side effects of the request—back through the R2R framework.\nExploitation requires remote access to the Retrieval Completion API. No prior authentication is explicitly required if the endpoint is exposed. The potential for post-exploitation includes, but is not limited to: port scanning of internal network infrastructure, extraction of sensitive information from internal services that rely on IP-based trust, and interaction with cloud provider metadata services (e.g., 169.254.169.254) to potentially escalate privileges by acquiring service account tokens. Given the nature of R2R, the exploit could also potentially be used to leverage the server as a proxy to obscure the origin of malicious traffic."
}