Onyx

Onyx

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 08.05.2026 03:51:11
  • Zuletzt bearbeitet 12.05.2026 13:58:54

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the calle...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 08.05.2026 03:49:56
  • Zuletzt bearbeitet 12.05.2026 14:08:02

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but n...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 22.07.2025 00:00:00
  • Zuletzt bearbeitet 09.10.2025 16:10:38

Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing inten...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 20.07.2025 14:02:07
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability, which was classified as critical, has been found in Onyx up to 0.29.1. This issue affects the function generate_simple_sql of the file backend/onyx/agents/agent_search/kb_search/nodes/a3_generate_simple_sql.py of the component Chat I...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 20.03.2025 10:11:20
  • Zuletzt bearbeitet 15.10.2025 13:15:52

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensi...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 20.03.2025 10:11:08
  • Zuletzt bearbeitet 03.04.2025 18:10:11

In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the...