VYPR
Vendor

Onyx Dot App

Products
2
CVEs
7
Across products
8
Status
Private

Products

2

Recent CVEs

7
  • CVE-2024-32881CriApr 26, 2024
    risk 0.57cvss 9.8epss 0.01

    Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the customer's slack bot,…

  • CVE-2024-7767HigMar 20, 2025
    risk 0.53cvss 8.1epss 0.01

    An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of…

  • CVE-2024-9612MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the front-end interface.…

  • CVE-2025-7894MedJul 20, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Onyx up to 0.29.1. This issue affects the function generate_simple_sql of the file backend/onyx/agents/agent_search/kb_search/nodes/a3_generate_simple_sql.py of the component Chat Interface. The manipulation…

  • CVE-2026-42277MedMay 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the caller is authenticated but never…

  • CVE-2026-42276MedMay 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session…

  • CVE-2025-51479MedJul 22, 2025
    risk 0.00cvss 5.4epss 0.00

    Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment…