Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85700— Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints

Quick assessment

Affected
onyx-dot-app onyx
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Onyx 4.6.6 未能正确限制对存储在 中的自定义工具凭据的访问,使得任何经过身份验证的用户都可以读取由管理员定义的 API 密钥。拥有基础身份验证权限的攻击者可以通过调用 或 端点,获取明文格式的授权头(authorization headers)以及第三方 API 凭据,并直接使用这些凭据访问上游 API。

CVSS 6.5 · Medium EPSS 0.29% · P21

Affected Version Matrix 1

VendorProduct Version RangeStatus
onyx-dot-app onyx ≤ 4.6.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85700

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext authorization headers and third-party API credentials, then use them to directly access upstream APIs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
onyx-dot-app onyx 0 ~ 4.6.6 -

II. Public POCs for CVE-2026-85700

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85700

登录查看更多情报信息。

Patches & Fixes for CVE-2026-85700 (1)

Vendor Advisories for CVE-2026-85700 (1)

Other References for CVE-2026-85700 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85700

No comments yet


Leave a comment