SciPhi-AI has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 7.3 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-82271Medium· 6.5R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations48CVE-2026-105148High· 7.3A vulnerability was identified in SciPhi-AI R2R up to 3.6.640CVE-2026-105147High· 7.3A vulnerability was determined in SciPhi-AI R2R up to 3.6.640
SciPhi-AI vulnerabilities
CVEs affecting SciPhi-AI, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-105147High· 7.3A vulnerability was determined in SciPhi-AI R2R up to 3.6.6
A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credenti…
CVE-2026-105148High· 7.3A vulnerability was identified in SciPhi-AI R2R up to 3.6.6
A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generati…
CVE-2026-82271Medium· 6.5PoCR2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename…