Trust & Security
R2R SQL Injection Breaks the Database Layer AI Agents Depend On
Two unauthenticated SQLi flaws in SciPhi-AI's RAG platform let attackers run arbitrary queries as PostgreSQL superuser – and the default config has auth turned off.
◆ Heath Callahan