AI Assistant Rabbit R1’s Code Vulnerability Exposes Users Data
ID: 97b0390f-9cab-58f9-b8ba-9db0c0456820
STIX ID: report--97b0390f-9cab-58f9-b8ba-9db0c0456820
Feed Name: cybersecurityNews.com
Threat Score
Rabbitude disclosed that Rabbit R1 had hardcoded API keys in its codebase, enabling access to third-party services (including ElevenLabs and SendGrid) and potentially every response produced by R1 devices; researchers demonstrated the issue, Rabbit has rotated most keys but a SendGrid key remained accessible, raising significant privacy and security concerns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
