Sceawere

Vulnerability Detail

CVE-2026-105148UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

R2R SSRF via API Base

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
SciPhi-AI
Product
R2R
Attack Type
Server-Side Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-04T13:16:55.733Z",
  "pubdate": "2026-10-04T13:16:55.733Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability has been identified in the SciPhi-AI R2R framework, specifically within the Retrieval Completion API Endpoint. This vulnerability, affecting versions up to 3.6.6, stems from improper validation of user-supplied input provided via the generation_config.api_base argument.\nBy manipulating the API base parameter, a remote, unauthenticated attacker can force the application to initiate unauthorized HTTP requests to arbitrary internal or external destinations. This facilitates the circumvention of network perimeters, potentially leading to unauthorized access to internal services, metadata endpoints (such as cloud instance metadata services), or local file system interaction via SSRF-capable protocols.\nThe risk is considered significant due to the availability of public exploits and the lack of vendor response, leaving the current user base exposed to exploitation. Security posture should be evaluated based on the ability of the R2R server to initiate outbound connections from its host environment.",
  "technicalDetails": "The vulnerability resides within the py/shared/abstractions/llm.py file, which handles the orchestration of LLM-based completion requests. The Retrieval Completion API Endpoint fails to properly sanitize or validate the generation_config.api_base parameter before incorporating it into the underlying networking library responsible for communicating with the specified LLM service provider.\nThe root cause is an insecure configuration handling mechanism where the application trusts the user-provided base URL string to define the destination for LLM API calls. Since the application blindly forwards this parameter to its request handler, an attacker can supply an arbitrary URL, including local addresses (e.g., http://127.0.0.1) or internal network segments that are otherwise inaccessible from the public internet.\nThe attack flow proceeds as follows: First, the attacker identifies the Retrieval Completion API endpoint as the vector. Second, the attacker crafts a malicious request payload where the generation_config object includes a modified api_base argument targeting a sensitive internal resource. Third, the application receives this input and uses it to construct an outbound request via py/shared/abstractions/llm.py. Fourth, the server executes the HTTP call to the attacker-defined URL, returning the response—or side effects of the request—back through the R2R framework.\nExploitation requires remote access to the Retrieval Completion API. No prior authentication is explicitly required if the endpoint is exposed. The potential for post-exploitation includes, but is not limited to: port scanning of internal network infrastructure, extraction of sensitive information from internal services that rely on IP-based trust, and interaction with cloud provider metadata services (e.g., 169.254.169.254) to potentially escalate privileges by acquiring service account tokens. Given the nature of R2R, the exploit could also potentially be used to leverage the server as a proxy to obscure the origin of malicious traffic."
}
CVE-2026-105148: R2R SSRF via API Base (HIGH Severity, CVSS: 7.3) | Sceawere