
Onyx CVE-2026-71424 can expose another user’s live MCP OAuth token to a BASIC_ACCESS user. Upgrade to 3.1.10, 3.2.14, or 4.0.0—and rotate tokens if exposure cannot be excluded. https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-q62f-rv3h-f822
Post summary
The advisory warns that CVE‑2026‑71424 can leak live OAuth tokens and provides specific version updates and a token rotation recommendation.
