R2R SQL Injection Breaks the Database Layer AI Agents Depend On
Two SQL injection flaws in SciPhi-AI’s R2R platform hand unauthenticated attackers full PostgreSQL superuser access Two critical SQL injection vulnerabilities in R2R, an open-source retrieval-augmented generation platform from SciPhi-AI, allow unauthenticated remote attackers to execute arbitrary queries with PostgreSQL superuser privileges. The flaws, disclosed by Ionix Threat Center this week, affect all R2R versions through…