CVE-2026-82526

Summary

R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account.

Affected Software

VendorProductVersion RangeStatus
SciPhi-AIR2R0 <= 3.6.6affected
SciPhi-AIR2R0 <= 9c5a94d151f90876bd7eb860f300a8fd662dc481affected

Weaknesses

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

References