Vulnerability  ·  2026-10-05

SciPhi-AI R2R hard-coded JWT / bcrypt / NaCl secrets allow token forgery and remote access

VulnerabilityHigh impactGlobalCVE-2026-105147
NVD published CVE-2026-105147 (CVSS 7.3, hard-coded credentials CWE-259/798) on 2026-10-04 for SciPhi-AI R2R up to 3.6.6. The JWT Secret Handler falls back to baked-in DEFAULT_BCRYPT_SECRET_KEY / DEFAULT_NACL_SECRET_KEY values, enabling token forgery. The exploit has been publicly disclosed. The vendor was contacted and did not respond.
A forgeable JWT secret in a self-hosted RAG framework means an attacker can authenticate to the R2R control plane as an admin, then use the platform's retrieval, ingestion, and agent-completion surfaces to tamper with knowledge bases, abuse the LLM provider credentials, or pivot into the deployment. This is the credential foundation that makes the related SSRF (CVE-2026-105148) exploitable end-to-end on default installs.
The JWT Secret Handler uses hard-coded DEFAULT_BCRYPT_SECRET_KEY / DEFAULT_NACL_SECRET_KEY defaults when no operator-configured secrets are set, so an attacker who knows the public default values can forge JWT bearer tokens and authenticate as any user against the unauthenticated remote API.
SciPhi-AI R2R up to 3.6.6 (JWT Secret Handler component)
No confirmed vendor patch. Operators must explicitly set strong, unique secrets for the JWT/bcrypt/NaCl handlers before exposing R2R, and restrict network exposure. Disclosure gist: https://gist.github.com/DReazer/6bc4f88053ec35f8358395bcc0d1a0bb
NVD CVE-2026-105147Disclosure gist
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →