CVE-2026-82271

Source
https://cve.org/CVERecord?id=CVE-2026-82271
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82271.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82271
Published
2026-08-28T16:18:54.164Z
Modified
2026-08-29T11:47:24.818009558Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
R2R Missing Ownership Check Allows Modifying Other Users' Conversations
Details

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82271.json",
    "cwe_ids": [
        "CWE-639"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/sciphi-ai/r2r

Affected ranges

Type
GIT
Repo
https://github.com/sciphi-ai/r2r
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.6.5"
        }
    ]
}

Affected versions

3.*
3.3.27
V3.*
V3.1.0
v0.*
v0.0.01
v0.0.1
v0.1.1
v0.1.2
v0.1.21
v0.1.22
v0.1.23
v0.1.24
v0.1.26
v0.1.27
v0.1.28
v0.1.29
v0.1.30
v0.1.31
v0.1.32
v0.1.33
v0.1.34
v0.1.35
v0.2.00
v0.2.01
v0.2.02
v0.2.03
v0.2.04
v0.2.10
v0.2.11
v0.2.12
v0.2.15
v0.2.16
v0.2.17
v0.2.39
v0.2.47
v0.2.51
v0.2.58
v0.2.59
v0.2.60
v0.2.61
v0.2.73
v0.2.74
v0.2.76
v0.2.85
v0.3.0
v2.*
v2.0.18
v2.0.3
v2.0.38
v2.0.64
v2.0.83
v2.0.84
v3.*
v3.0.0
v3.2.0
v3.2.30
v3.3.0
v3.3.28
v3.3.29
v3.3.30
v3.4.0
v3.4.2
v3.4.3
v3.4.4
v3.4.5
v3.4.6
v3.5.0
v3.5.1
v3.5.10
v3.5.11
v3.5.12
v3.5.13
v3.5.15
v3.5.16
v3.5.17
v3.5.18
v3.5.19
v3.5.2
v3.5.3
v3.5.6
v3.5.7
v3.5.8
v3.5.9
v3.6.0
v3.6.1
v3.6.2
v3.6.3
v3.6.4
v3.6.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82271.json"