Skip to content

Menu
  • Home
Menu

CVE-2026-71424 – Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers

Posted on August 18, 2026
CVE ID :CVE-2026-71424

Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago

Description :Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx’s GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user’s OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in backend/onyx/server/features/mcp/api.py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_server_to_api_mcp_server returns that row through auth_template.headers to any BASIC_ACCESS user. This issue is fixed in versions 3.1.10, 3.2.14, and 4.0.0.

Severity: 9.6 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 3

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme