CVE-2026-71424 - Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers
CVE ID : CVE-2026-71424
Published : Aug. 17, 2026, 10:17 p. m.
• 50 minutes ago
Description : Onyx is an open-source AI platform. Prior to 3. 1. 10, 3. 2. 14, and 4. 0. 0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage. set_tokens and OnyxTokenStorage. set_client_info in backend/onyx/server/features/mcp/api.
py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_server_to_api_mcp_server returns that row through auth_template. headers to any BASIC_ACCESS user. This issue is fixed in versions 3. 1. 10, 3. 2. 14, and 4. 0. 0.
Severity: 9.6
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...