VYPR

R2r

by Sciphi AI

CVEs (1)

  • CVE-2026-82271MedAug 28, 2026
    risk 0.42cvss 6.5epss

    R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to…