Junglewise Threat Intelligence

CVE-2026-85178: Helicone VaultManager authorization bypass in provider key retrieval

CVE-2026-85178 · Severity: high · CVSS 7.7 · Published 2026-09-03

Executive brief

Helicone is an open-source platform for monitoring and evaluating large language models. The vulnerability allows administrators or owners of any organization account to retrieve decrypted API credentials (including OpenAI, Anthropic, and Bedrock keys) belonging to other organizations. This could lead to unauthorized access to third-party services and exposure of sensitive authentication tokens.

Technical details

The VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate that the requesting user's organization matches the vault key's organization identifier. An authenticated attacker with admin or owner privileges can query arbitrary provider key IDs to retrieve decrypted upstream provider credentials for other tenants, exposing plaintext API keys. The vulnerability is an authorization bypass (missing multi-tenant isolation on a sensitive data retrieval operation). The attack requires valid authentication and admin/owner privileges within any organization. A patch was committed on 2026-08-30 that adds organization filtering (AND org_id = $2) to the SQL query.

Affected products

  • Helicone Helicone <unknown

Timeline

  • 2026-09-03: disclosed
  • 2026-08-30: patched: Security patch committed via PR #5801; adds organization filtering to VaultManager queries

References