Junglewise Threat Intelligence

CVE-2026-85700: Onyx credential disclosure in custom tool endpoints

CVE-2026-85700 · Severity: medium · CVSS 6.5 · Published 2026-09-04

Technologies: Onyx. Vendors: Onyx.

Executive brief

Onyx is an open-source AI chat platform that allows administrators to integrate external tools and APIs. A flaw in versions 4.6.6 and earlier fails to properly restrict access to administrator-defined API credentials and authorization headers stored in custom tool configurations. Any authenticated user can retrieve these plaintext secrets through the tool API endpoints and then use them to directly access upstream services, potentially compromising third-party integrations and sensitive data.

Technical details

The vulnerability is an authorization bypass (CWE-639) in the custom tool API endpoints (/tool and /tool/{tool_id}). Authenticated users can call GET requests to retrieve custom tool definitions stored in the custom_headers field, which contains plaintext API keys and authorization headers meant only for administrators to configure. The root cause is insufficient access control in the api.py file of the tool feature module. No authentication bypass is required—only valid user credentials are needed. An attacker with basic authentication can enumerate tools and exfiltrate all embedded credentials, then use them to directly access third-party APIs, potentially leading to unauthorized access, data exfiltration, or service disruption on upstream systems.

Affected products

  • Onyx Onyx 4.6.6 and earlier

Timeline

  • 2026-09-04: disclosed

References

Related threats