Executive brief
Onyx is an open-source AI platform that manages external integrations through MCP (Model Context Protocol) server connections. A flaw in the API endpoints allows any authenticated user to retrieve OAuth credentials and authorization headers belonging to other users by reading shared configuration data, enabling account takeover and unauthorized API access.
Technical details
The vulnerability is an information disclosure flaw in Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints. The root cause lies in OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info functions in backend/onyx/server/features/mcp/api.py, which incorrectly store per-user OAuth tokens in a shared admin MCPConnectionConfig database row. The _db_mcp_server_to_api_mcp_server function then returns this shared row—including auth_template.headers containing OAuth Authorization headers—to any user with BASIC_ACCESS privilege. An authenticated attacker can call these endpoints to retrieve other users' OAuth credentials. The vulnerability is fixed in versions 3.1.10, 3.2.14, and 4.0.0.
Affected products
- Onyx Onyx prior to 3.1.10, 3.2.14, and 4.0.0
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched: Fixed in versions 3.1.10, 3.2.14, and 4.0.0