Browse all 4 CVE security advisories affecting onyx-dot-app. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-63178 | Onyx Curator-scope IDOR: any curator can modify membership of arbitrary user groups via unscoped PATCH /manage/admin/user-group/{id} and /add-users leading to cross-group document disclosure — onyxCWE-639 | 6.5 | Medium | 2026-08-17 |
| CVE-2026-71424 | Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers — onyxCWE-200 | 9.6 | Critical | 2026-08-17 |
| CVE-2026-42277 | Onyx: IDOR in /chat/file/{file_id} allows any authenticated user to download other users files — onyxCWE-639 | 6.5 | Medium | 2026-05-08 |
| CVE-2026-42276 | Onyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other users chat sessions — onyxCWE-639 | 4.3 | Medium | 2026-05-08 |
This page lists every published CVE security advisory associated with onyx-dot-app. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.