CVE-2026-105147

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets6 URLs
Full discourse1 post
  • Code Solutions@CodeSolutionsIL

    Don’t Panic Digest Inform. Gate. Then automate. News — SciPhi-AI R2R default signing key and caller-chosen endpoint (CVE-2026-105147 + CVE-2026-105148, CVSS 3.1 7.3 HIGH each): on a default install, an empty secret setting falls back to a signing key that sits in the public source, so an outsider can forge an admin token; and the completion/agent API lets the caller pick the model endpoint, so the server can be pointed at any URL and, with some model prefixes, send along its own model-provider key. Affected 3.6.0–3.6.6 (CNA VulDB). No vendor patch yet (vendor “did not respond”); not in CISA KEV; no in-the-wild use stated. Operator read: an SI (super intelligence) app that ships a default secret or lets the request choose where it calls can hand out admin access and its own provider key — set a unique secret, require auth, keep outbound endpoints in server config only, and keep it off the open internet. https://nvd.nist.gov/vuln/detail/CVE-2026-105147 Related: Anthropic on expanding cyber verification access controls (Oct 6) — as Anthropic frames it, gate stronger dual-use access by verified role, keep a short always-blocked list, keep logs so misuse can be seen, and test those gates before relying on them. Our Plainwrap daily notes: https://x.com/CodeSolutionsIL/status/2107886008054460908 https://www.anthropic.com/news/cyber-verification-program More — American Optimist Ep 164 / Joe Lonsdale × Anthropic’s Sholto Douglas & Nicholas Marwell (dual-use risk, offense vs defense, open vs closed thresholds, ~19:30–40:12): What’s in it: Anthropic staff walk through near-term cyber and bio dual-use risk, offense vs defense (cyber may flip defense-dominant sooner; bio stays hard), push back on a regulatory-capture read of their safety stance, say open and closed should meet the same capability thresholds, refuse a US slowdown that lets China race ahead without trusted coordination, and argue distillation copies the frontier without funding the next training jump. Our takeaway: Treat dual-use tools as offense-heavy until defense infrastructure is real — same safety bar for open and closed, and skip a US-only slowdown that leaves China racing alone. Notes of a public interview, not product guidance; timing, policy, and lab-stance claims are as discussed by the speakers, not verified, and panel opinions are not endorsed. https://gist.github.com/CodeSolutionsLLC/0c2638a041ddd5a0a3155eb177834181 https://x.com/AmOptimistShow/status/2106115609306226982 https://codesolutionsllc.com/news

    1000065
    11 followersView on X

Explore more