What happened
NVD published CVE-2026-105147 (CVSS 7.3, hard-coded credentials CWE-259/798) on 2026-10-04 for SciPhi-AI R2R up to 3.6.6. The JWT Secret Handler falls back to baked-in DEFAULT_BCRYPT_SECRET_KEY / DEFAULT_NACL_SECRET_KEY values, enabling token forgery. The exploit has been publicly disclosed. The vendor was contacted and did not respond.
Why it matters
A forgeable JWT secret in a self-hosted RAG framework means an attacker can authenticate to the R2R control plane as an admin, then use the platform's retrieval, ingestion, and agent-completion surfaces to tamper with knowledge bases, abuse the LLM provider credentials, or pivot into the deployment. This is the credential foundation that makes the related SSRF (CVE-2026-105148) exploitable end-to-end on default installs.
Attack vector
The JWT Secret Handler uses hard-coded DEFAULT_BCRYPT_SECRET_KEY / DEFAULT_NACL_SECRET_KEY defaults when no operator-configured secrets are set, so an attacker who knows the public default values can forge JWT bearer tokens and authenticate as any user against the unauthenticated remote API.
Affected systems
SciPhi-AI R2R up to 3.6.6 (JWT Secret Handler component)
Mitigation
No confirmed vendor patch. Operators must explicitly set strong, unique secrets for the JWT/bcrypt/NaCl handlers before exposing R2R, and restrict network exposure. Disclosure gist: https://gist.github.com/DReazer/6bc4f88053ec35f8358395bcc0d1a0bb