VYPR

helicone

by Helicone

CVEs (1)

  • CVE-2026-85178HigSep 3, 2026
    risk 0.43cvss 7.7epss

    Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can…