CVE-2026-42277

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the caller is authenticated but never checks that the file belongs to them. An attacker who knows or obtains a file UUID can access confidential documents, chat attachments, and other files uploaded by any user in the system. This issue has been patched in versions 3.0.9, 3.1.6, and 3.2.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:onyx:onyx:*:*:*:*:*:*:*:*
cpe:2.3:a:onyx:onyx:*:*:*:*:*:*:*:*
cpe:2.3:a:onyx:onyx:*:*:*:*:*:*:*:*

History

12 May 2026, 13:58

Type Values Removed Values Added
References () https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-vg3h-35f7-7w6r - () https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-vg3h-35f7-7w6r - Vendor Advisory
CPE cpe:2.3:a:onyx:onyx:*:*:*:*:*:*:*:*
First Time Onyx
Onyx onyx

08 May 2026, 22:16

Type Values Removed Values Added
References () https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-vg3h-35f7-7w6r - () https://github.com/onyx-dot-app/onyx/security/advisories/GHSA-vg3h-35f7-7w6r -

08 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 05:16

Updated : 2026-05-12 13:58


NVD link : CVE-2026-42277

Mitre link : CVE-2026-42277

CVE.ORG link : CVE-2026-42277


JSON object : View

Products Affected

onyx

  • onyx
CWE
CWE-639

Authorization Bypass Through User-Controlled Key