CVE-2026-105148: Server-Side Request Forgery in SciPhi-AI R2R
Description
CVE-2026-105148 is a server-side request forgery (SSRF) vulnerability in SciPhi-AI R2R affecting versions 3.6.0 through 3.6.6. The flaw exists in the Retrieval Completion API Endpoint, specifically in the file py/shared/abstractions/llm.py, where manipulation of the argument generation_config.api_base can lead to SSRF. The vulnerability can be exploited remotely. Public exploit code is available, but there is no indication of active exploitation in the wild. The vendor has not responded to disclosure attempts and no patch or mitigation guidance is currently available.
CVSS v4.0
Score 6.9medium
Affected software
SciPhi-AI
R2R
pkg:pypi/sciphi-ai-r2rcpe:2.3:a:sciphi-ai:r2r:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in SciPhi-AI R2R (up to version 3.6.6) allows an attacker to perform server-side request forgery by manipulating the generation_config.api_base argument in the Retrieval Completion API Endpoint component. The vulnerable code is located in py/shared/abstractions/llm.py. The attack can be launched remotely without authentication. Public exploit code exists, increasing the risk of exploitation. The vendor has not provided any response or patch, and no official remediation is documented.
Potential Impact
Successful exploitation of this SSRF vulnerability could allow an attacker to make unauthorized requests from the vulnerable server to internal or external systems. This could lead to information disclosure or interaction with internal services not normally accessible externally. The CVSS 4.0 base score is 6.9 (medium severity), reflecting network attack vector, low complexity, no privileges or user interaction required, but limited confidentiality, integrity, and availability impacts.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Since the vendor has not responded and no fixes are published, users should consider implementing network-level protections such as restricting outbound requests from the affected component to trusted destinations only, if feasible. Monitor for unusual outbound traffic patterns. Check the vendor advisory regularly for updates or patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-10-03T18:05:17.570Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac2465912601ec6a317381d
Added to database: 10/04/2026, 12:28:09 UTC
Last enriched: 10/04/2026, 12:43:06 UTC
Last updated: 10/04/2026, 16:16:14 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.