#2297·R2R

Security: request for a private disclosure channel (unpatched authorization issue)

Author: dmitrymaranikCreated Jun 29, 2026Updated Jun 29, 2026

Hi R2R / SciPhi team,

I've found what appears to be an unpatched cross-tenant authorization issue in R2R (affecting the multi-tenant / auth-enabled posture, i.e. require_authentication=true / SciPhi Cloud) and would like to report it responsibly without posting details in a public issue.

Could you please open a private channel — either:

  • enable Private Vulnerability Reporting on this repo (Settings -> Code security & analysis -> Private vulnerability reporting), or
  • share a security email I can send the full report to?

I have the affected files, a write-up, and suggested fixes (all small) ready to send privately.

Thanks! — Dmitry Maranik (Sectum AI, https://sectum.ai)