HIGH
R2R 3.6.6 SQL Injection via Retrieval Search Filter Key
Published Sep 3, 2026
8.7
HIGHCVSS 4.0
EPSS 0.46%
Description
R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the retrieval search endpoint. Attackers can exploit the direct interpolation of filter keys into the SQL WHERE clause without parameterization or escaping to perform time-based and boolean-based data exfiltration from the application database.
Affected products
-
- Version 0StatusaffectedConstraints<=3.6.6
- Version
-
- Version 0StatusaffectedConstraints
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/SciPhi-AI/R2R/issues/2308 technical-descriptionexploit
- https://www.vulncheck.com/advisories/r2r-sql-injection-via-retrieval-search-filter-key third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/SciPhi-AI/R2R/issues/2308 | technical-descriptionexploit | |
| https://www.vulncheck.com/advisories/r2r-sql-injection-via-retrieval-search-filter-key | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 3, 2026
Updated Sep 4, 2026
Reserved Aug 29, 2026
Link CVE-2026-82527
CISA Vulnrichment
Updated Sep 4, 2026