PatchSiren

onyx-dot-app CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL onyx-dot-app CVE published 2026-08-17

CVE-2026-71424

CVE-2026-71424 is a critical vulnerability in Onyx, an open-source AI platform, affecting versions prior to 3.1.10, 3.2.14, and 4.0.0. The issue allows any BASIC_ACCESS user to access another user's OAuth Authorization header due to improper token storage in the backend. This vulnerability has a CVSS score of 9.6 and is considered CRITICAL. Affected deployments should prioritize verification of Onyx serve [truncated]

MEDIUM onyx-dot-app CVE published 2026-08-17

CVE-2026-63178

CVE-2026-63178 is a vulnerability in Onyx Enterprise Edition's user group management endpoints, allowing a curator to add accounts to arbitrary groups and potentially obtain document access. The issue is fixed in version 4.3.0. This vulnerability affects Onyx Enterprise Edition, specifically the PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endp [truncated]