CVE-2026-71424Patch

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in backend/onyx/server/features/mcp/api.py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_server_to_api_mcp_server returns that row through auth_template.headers to any BASIC_ACCESS user. This issue is fixed in versions 3.1.10, 3.2.14, and 4.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 108-18
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • iSECTECH@isectech_
    Patch

    Onyx CVE-2026-71424 can expose another user’s live MCP OAuth token to a BASIC_ACCESS user. Upgrade to 3.1.10, 3.2.14, or 4.0.0—and rotate tokens if exposure cannot be excluded. https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-q62f-rv3h-f822

    Post summary

    The advisory warns that CVE‑2026‑71424 can leak live OAuth tokens and provides specific version updates and a token rotation recommendation.

    0000026
    86 followersView on X

Explore more