logo

AI Assistant Rabbit R1’s Code Vulnerability Exposes Users Data

ID: 97b0390f-9cab-58f9-b8ba-9db0c0456820

STIX ID: report--97b0390f-9cab-58f9-b8ba-9db0c0456820

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2024-06-27

Date Updated: 2026-04-21

Author: Dhivya

...
...

Rabbitude disclosed that Rabbit R1 had hardcoded API keys in its codebase, enabling access to third-party services (including ElevenLabs and SendGrid) and potentially every response produced by R1 devices; researchers demonstrated the issue, Rabbit has rotated most keys but a SendGrid key remained accessible, raising significant privacy and security concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.