CVE-2026-105148: SciPhi-AI R2R Retrieval Completion API Endpoint llm.py server-side request forgery
A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generationconfig.apibase leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
SciPhi-AI R2R versions up to and including 3.6.6 are identified as affected. The issue is in the Retrieval Completion API Endpoint, in code associated with py/shared/abstractions/llm.py.
What does an attacker need to exploit this issue?
The attack can be launched remotely and requires manipulation of the generation_config.api_base argument. The provided vector indicates no privileges or user interaction are required.
Is public exploit code available?
Yes. The exploit is publicly available and may be used by attackers.
Is a vendor fix or workaround documented?
No vendor response, fix, or workaround is provided in the available data. If patching cannot be performed immediately, the data does not specify a validated mitigation.