Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
R2R Missing Ownership Check Allows Modifying Other Users' Conversations
Vulnerability Description
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
SciPhi-AI R2R 授权问题漏洞
Vulnerability Description
SciPhi-AI R2R是SciPhi-AI组织的一个将检索与生成流程进行编排的智能引擎。 SciPhi-AI R2R 3.6.5及之前版本存在授权问题漏洞,该漏洞源于对话更新和消息处理程序未正确验证用户所有权,可能导致经过身份验证的用户修改其他用户的对话,通过提供任意对话标识符重命名对话并向其他用户的对话历史追加消息,破坏状态并注入恶意内容。
CVSS Information
N/A
Vulnerability Type
N/A