CVE-2026-71424 - Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers
Brief
CVE ID : CVE-2026-71424
Published : Aug. 17, 2026, 10:17 p. m.
- 50 minutes ago
Description : Onyx is an open-source AI platform. Prior to 3.
- 10, 3.
- 14, and 4.
- 0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage. set_tokens and OnyxTokenStorage. set_client_info in backend/onyx/server/features/mcp/api.
py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_server_to_api_mcp_server returns that row through auth_template. headers to any BASIC_ACCESS user. This issue is fixed in versions 3.
- 10, 3.
- 14, and 4.
- 0.
Severity: 9.6
- CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
