Vendor
SciPhi-AI R2R versions up to 3.6.6 contain a vulnerability in the JWT Secret Handler component that uses hard-coded credentials, allowing remote attackers to bypass authentication.