CVE-2026-105148 | SciPhi-AI R2R up to 3.6.6 Retrieval Completion API Endpoint llm.py generation_config.api_base server-side request forgery
A vulnerability categorized as critical has been discovered in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-105148. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More