All 3 CVE vulnerabilities found in R2R, with AI-generated Chinese analysis, references, and POCs.
Vendor: SciPhi-AI
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-82527 | R2R 3.6.6 SQL Injection via Retrieval Search Filter Key CWE-89 | 7.5 | High | 2026-09-03 |
| CVE-2026-82526 | R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint CWE-89 | 9.8 | Critical | 2026-09-03 |
| CVE-2026-82271 | R2R Missing Ownership Check Allows Modifying Other Users' Conversations CWE-639 | 6.5 | Medium | 2026-08-28 |
All 3 known CVE vulnerabilities affecting R2R with full Chinese analysis, references, and POCs where available.