
CVE-2026-42277 Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any oth… https://www.cve.org/CVERecord?id=CVE-2026-42277
Post summary
CVE-2026-42277 permits authenticated users to download any files via the /chat/file/{file_id} endpoint in Onyx; the issue was addressed in versions 3.0.9, 3.1.6, and 3.2.6.

