← Back to feed
AI SecurityEmerging1 sourceAug 17, 2026 · 22:17via CVEFeed

CVE-2026-71424 - Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers

Brief

CVE ID : CVE-2026-71424

Published : Aug. 17, 2026, 10:17 p. m.

  • 50 minutes ago

Description : Onyx is an open-source AI platform. Prior to 3.

  • 10, 3.
  • 14, and 4.
  • 0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage. set_tokens and OnyxTokenStorage. set_client_info in backend/onyx/server/features/mcp/api.

py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_server_to_api_mcp_server returns that row through auth_template. headers to any BASIC_ACCESS user. This issue is fixed in versions 3.

  • 10, 3.
  • 14, and 4.
  • 0.

Severity: 9.6

  • CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed