PT-2026-85230 · R2R · R2R
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
R2R versions prior to 3.6.7
Description
Unauthenticated attackers can perform time-based and boolean-based data exfiltration from the application database. This is possible due to the direct interpolation of filter keys into the SQL WHERE clause without parameterization or escaping, allowing the injection of SQL predicates into the chunks search query via the retrieval search endpoint using the
filter key parameter.Recommendations
Update R2R to version 3.6.7 or later.
As a temporary workaround, restrict access to the retrieval search endpoint to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
R2R