{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/sciphi-ai/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sciphi:r2r:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105147"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["R2R (\u003c= 3.6.6)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SciPhi-AI"],"content_html":"\u003cp\u003eSciPhi-AI R2R versions up to and including 3.6.6 contain a security vulnerability in the JWT Secret Handler component. The application improperly utilizes hard-coded credentials for DEFAULT_BCRYPT_SECRET_KEY and DEFAULT_NACL_SECRET_KEY, which are used to sign and verify JSON Web Tokens (JWT). An unauthenticated remote attacker can leverage these known, static values to forge authentication tokens, potentially leading to unauthorized access to the application and elevated privileges. The vulnerability has been publicly disclosed and is susceptible to exploitation, posing a significant risk to R2R deployments. As the vendor has not responded to disclosure attempts, no official patch is currently available, necessitating immediate mitigation through configuration hardening.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote attackers to bypass authentication mechanisms. If exploited, an attacker can gain administrative access to the R2R platform, leading to potential data exfiltration, unauthorized modification of configurations, or total compromise of the R2R instance. The scope of impact is limited to organizations running SciPhi-AI R2R versions up to 3.6.6 in internet-facing environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of SciPhi-AI R2R in the environment and ensure they are isolated from public network access.\u003c/li\u003e\n\u003cli\u003eReview application configuration files for the presence of the default values for DEFAULT_BCRYPT_SECRET_KEY and DEFAULT_NACL_SECRET_KEY and rotate them to unique, cryptographically strong values.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to R2R administrative endpoints to known, trusted management subnets.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual authentication patterns or signs of credential stuffing and unauthorized token usage, specifically looking for tokens that appear to be signed using the default, hard-coded key values if they are publicly known.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T14:52:37Z","date_published":"2026-10-04T14:52:37Z","id":"https://feed.craftedsignal.io/briefs/2026-10-sciphi-r2r-hardcoded-secret/","summary":"SciPhi-AI R2R versions up to 3.6.6 contain a vulnerability in the JWT Secret Handler component that uses hard-coded credentials, allowing remote attackers to bypass authentication.","title":"Hard-coded JWT Secrets in SciPhi-AI R2R","url":"https://feed.craftedsignal.io/briefs/2026-10-sciphi-r2r-hardcoded-secret/"}],"language":"en","title":"CraftedSignal Threat Feed - SciPhi-AI","version":"https://jsonfeed.org/version/1.1"}